@@ -2352,7 +2352,9 @@ Note for Gisela, Clauses have been renumbered for consistency.
The product shall, by default, use State-of-the-Art cryptography algorithms listed in (CRY-SOTA), to be used for the supported security mechanism of the product where applicable.
> NOTE 1: The use of security mechanism e.g. authentication, access control, secure communication, secure storage and secure update are described in the main text of this standard.
> NOTE 2: Cryptographic algorithm primitives (in short, algorithms e.g. public- and private-key encryption algorithms, hash functions, authentication codes, digital signatures) are classified as CRY-SOTA if they are listed in the [ACM] document and are suitable for the implementation of supported security mechanisms of the product.
> NOTE 3 Supporting evidence options that an algorithm, which is not included in CRY-SOTA, is applicable and suitable for the respective use case, are listed in the related assessment criteria ( K.1.2.1) clause.
@@ -2404,13 +2406,13 @@ For every security mechanism and for every used algorithm, which is reachable ov
Where applicable the product shall by default be prepared to update cryptographic algorithm used for the supported security mechanism of the product to maintain when there are indications that the used cryptographic
algorithm will not stay SOTA anymore within the intended lifetime of the product.
NOTE 4: To maintain SOTA for cryptographic algorithm within the intended lifetime of the product concepts to consider are crypto agility additional to the capability of updating cryptographic algorithms on the product in accordance to Secure Update and Secure Communication mechanism.
> NOTE 4: To maintain SOTA for cryptographic algorithm within the intended lifetime of the product concepts to consider are crypto agility additional to the capability of updating cryptographic algorithms on the product in accordance to Secure Update and Secure Communication mechanism.
NOTE 5: The [ACM] listing has two classes of SOTA algorithms; Legacy mechanisms with an expiry date as defined in ACM, and Recommended mechanisms with no set expiry date.
> NOTE 5: The [ACM] listing has two classes of SOTA algorithms; Legacy mechanisms with an expiry date as defined in ACM, and Recommended mechanisms with no set expiry date.
NOTE 6: For products or components of products that cannot have their cryptographic algorithms updated for example if the implementation or part uses a hardware-based root of trust, it is important that the intended lifetime of the equipment does not exceed the recommended usage lifetime of the cryptographic algorithms used by the product. Thereby the implementation of an algorithm can include the specific implementation of their parameters
> NOTE 6: For products or components of products that cannot have their cryptographic algorithms updated for example if the implementation or part uses a hardware-based root of trust, it is important that the intended lifetime of the equipment does not exceed the recommended usage lifetime of the cryptographic algorithms used by the product. Thereby the implementation of an algorithm can include the specific implementation of their parameters
NOTE 7: If a component storing the algorithm or corresponding parameters of a main product is replaced
> NOTE 7: If a component storing the algorithm or corresponding parameters of a main product is replaced
by a new component, the product is considered as a new product according to the New Legislative Framework
Blue Guide4, if the replacement provides a substantial modification to the main product