@@ -3251,7 +3251,7 @@ The risk and their applicability to use cases defined in Annex U are presented i
# Annex K (normative):
# Vertical specific state of the art cryptography
## Vertical specific state of the art cryptography
## K.1 General
@@ -3263,26 +3263,26 @@ For the purposes of the present document, a cryptographic algorithm, scheme or p
A cryptographic algorithm, scheme or protocol is CRY-SOTA where at least one of the following applies:
1.ACM-listed: it is listed as Recommended (or equivalent) in the European Cybersecurity Certification Group’s Agreed Cryptographic Mechanisms catalogue (ACM) [1];
i) ACM-listed: it is listed as Recommended (or equivalent) in the European Cybersecurity Certification Group’s Agreed Cryptographic Mechanisms catalogue (ACM) [1];
2. ACM-extended (recognized catalogue): it is not listed in the ACM, and it is listed as Recommended (or equivalent), and is not marked as deprecated, legacy-only or disallowed at the time of the conformity assessment, in any of the following recognized public cryptographic catalogues:
ii) ACM-extended (recognized catalogue): it is not listed in the ACM, and it is listed as Recommended (or equivalent), and is not marked as deprecated, legacy-only or disallowed at the time of the conformity assessment, in any of the following recognized public cryptographic catalogues:
-NIST publications in the Special Publication 800 series, the FIPS series, and the associated CAVP/ACVP test-vector programmes;
o NIST publications in the Special Publication 800 series, the FIPS series, and the associated CAVP/ACVP test-vector programmes;
-BSI TR-02102 series [2];
o BSI TR-02102 series [2];
- ANSSI Référentiel Général de Sécurité, Annex B2 [3];
o ANSSI Référentiel Général de Sécurité, Annex B2 [3];
- ANSSI Référentiel Général de Sécurité, Annex B2 [3];
o ANSSI Référentiel Général de Sécurité, Annex B2 [3];
- a sector-specific cryptographic algorithm catalogue maintained by a recognized standards-development organization such as ETSI, 3GPP, ITU-T, IEEE and IETF (see EXAMPLE 2);
o a sector-specific cryptographic algorithm catalogue maintained by a recognized standards-development organization such as ETSI, 3GPP, ITU-T, IEEE and IETF (see EXAMPLE 2);
3.iii) ACM-extended (vertical content): it is listed in the normative cryptographic content of the present document for routers, modems and switches (see clauses K.3 through K.8).
iii) ACM-extended (vertical content): it is listed in the normative cryptographic content of the present document for routers, modems and switches (see clauses K.3 through K.8).
A cryptographic algorithm, scheme or protocol that is not CRY-SOTA under items i), ii) or iii) may be used only as follows:
4. Interoperability-based: it is required for a specific product function to comply with a well-defined external specification or external requirement, and its use meets all of the conditions for legacy interoperability set out in clause K.2.4 (2). Inclusion of a cryptographic algorithm, scheme or protocol under this route does not classify it as CRY-SOTA.
iv) Interoperability-based: it is required for a specific product function to comply with a well-defined external specification or external requirement, and its use meets all of the conditions for legacy interoperability set out in clause K.2.4 (2). Inclusion of a cryptographic algorithm, scheme or protocol under this route does not classify it as CRY-SOTA.