
Cisco Intrusion Prevention System Security Target
Exceptions to
Shall/Shall Not
Statement(s)
“a random nonce
should be used”
5.5.1 Domain
Parameter Generation
“If the appropriate
security strength does
not have an FFC
parameter set, then
Elliptic Curve
Cryptography should
be used”
5.5.1.1 FFC Domain
Parameter Generation
5.5.1.2 ECC Domain
Parameter Generation
5.5.2 Assurances of
Domain Parameter
Validity
5.5.3 Domain
Parameter Management
5.6 Private and Public
Keys
5.6.1 Private/Public
Key Pair Generation
5.6.1.1 FFC Key Pair
Generation
5.6.1.2 ECC Key Pair
Generation
5.6.2 Assurances of the
Arithmetic Validity of a
Public Key
5.6.2.1 Owner
Assurances of Static
Public Key Validity
None. Static key is
not supported.
5.6.2.2 Recipient
Assurances of Static
Public Key Validity
None. Static key is
not supported.
5.6.2.3 Recipient
Assurances of
Ephemeral Public Key
Validity
5.6.2.4 FFC Full Public
Key Validation Routine
5.6.2.5 ECC Full
Public Key Validation
Routine
5.6.2.6 ECC Partial
Public Key Validation
Routine
5.6.3 Assurances of the
Possession of a Static
None. Static key is
not supported.
Kommentare zu diesen Handbüchern