Commit 66aae35c authored by Giulio Di Clemente's avatar Giulio Di Clemente
Browse files

Edit EN-304-624.md K.2.3

parent b0f22b05
Loading
Loading
Loading
Loading
+14 −2
Original line number Diff line number Diff line
@@ -3295,8 +3295,20 @@ A cryptographic algorithm, scheme or protocol that is not CRY-SOTA under items i

  - NOTE 3:	A cryptographic mechanism composed of more than one cryptographic primitive (for example a hybrid key-encapsulation mechanism or a hybrid signature scheme) inherits the most restrictive classification of its constituent primitives. A hybrid construction including a Legacy or Deprecated component is therefore classified as Legacy or Deprecated, regardless of the classification of the other components.



## K.2 Assessment criteria for compliance with cryptographic requirements
### K.2.1 Assessment objective
The purpose of this assessment case is to verify that, for every cryptographic algorithm, scheme or protocol used by a security mechanism of the product, appropriate evidence is provided demonstrating classification as CRY-SOTA in accordance with clause K.1, by reference to one of paths i), ii) or iii) of that clause.
### K.2.2 Assessment preparation
Preconditions for the assessment:
- •	where the product has a default configuration, that default configuration shall be used for the assessment;
- •	otherwise, the delivery-state configuration shall be used (i.e. the configuration of the product as made available on the market in accordance with Annex I, Part I, point (2)(b) of Regulation (EU) 2024/2847 [i.1]);
- •	the manufacturer shall make available a list identifying every security mechanism of the product, the cryptographic algorithm, scheme or protocol used by that mechanism, the parameters in use, and whether the algorithm forms part of the default or delivery-state configuration.
### K.2.3 Assessment activities
For every security mechanism identified under the preceding clause, the assessor shall:
- 1)	review the documentation provided and confirm that, for each algorithm in use, the manufacturer has identified the path of clause K.1 (i, ii, or iii) by which the algorithm is classified as CRY-SOTA, and the corresponding catalogue entry or clause reference;
- 2)	verify that the catalogue entry or clause reference cited under (1) exists, is published, and is not marked as deprecated, legacy-only or disallowed at the time of the assessment;
- 3)	inspect the product in the configuration identified under the preceding clause and confirm that the cryptographic algorithm and parameters in use match the documented configuration;
- 4)	where the manufacturer has documented the use of an algorithm that is not classified as CRY-SOTA under any path of clause K.1, verify that the conditions for legacy interoperability are met.