© The Author(s), under exclusive license to APress Media, LLC, part of Springer Nature 2024
D. Johnston, R. FantDesigning to FIPS-140https://doi.org/10.1007/979-8-8688-0125-9_9

9. Entropy Source Validation Certification

David Johnston1   and Richard Fant2
(1)
Hillsboro, OR, USA
(2)
Austin, TX, USA
 

Most FIPS modules will require an RNG (random number generator) for things like key and nonce generation and so will require entropy certification for the noise source within the RNG.

FIPS references SP800-90A for the random number generator requirements. SP800-90C is still in draft form at the time of writing, and SP800-90B is in a revision process and so will have some updates in the 2024–2025 time period.

SP800-90B is the standard concerned with noise sources, ...

Get Designing to FIPS-140: A Guide for Engineers and Programmers now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.