Cryptography – SSP Zeroization
A module shall provide methods to zeroize all CSPs (including temporarily stored values) within the module.
Once a CSP is zeroized, the CSP shall not be retrievable from the module. Zeroization of PSPs, encrypted CSPs, or CSPs otherwise physically or logically protected within an additional embedded validated module (meeting the requirements of this standard) is not required at levels below Security Level 5.
Keys used only to perform pre-operational self-tests shall be [..]
Cryptographic Module Specification
A cryptographic module shall be a set of hardware and software that implements cryptographic functions or processes, including cryptographic algorithms and, optionally, key generation, and is contained within a defined cryptographic boundary.
In an Approved mode of operation a cryptographic module shall implement at least one Approved or Allowed security function. Certain non-Approved security functions are allowed for use in an Approved mode of operation. Allowed security functions used in an [..]
Cryptography – Acronyms
The following acronyms and abbreviations are used throughout this standard:
CMS Configuration Management System
CSP Critical Security Parameter
DPA Differential Power Analysis
EDC Error Detection Code
EFP Environmental Failure Protection [..]