Master'sOpen Access

FIPS 140 ve ISO/IEC 15408'e göre şifreleme modülleridoğrulama süreci

2020
0 views
0 downloads
Advisor: Doç. Dr. Ali Doğanaksoy ; Doç. Dr. Oğuz Yayla

Abstract (EN)

With the advancement of technology, questions have arisen regarding the reliability of information technology products. Some standards have emerged to ensure the reliability of these products and to validate this reliability internationally. One of the standards issued to meet this need is ISO/IEC 15408 Common Criteria Standard. Thanks to this standard, the relevant institutions authorized to evaluate information technology products are evaluated and the reliability of this product is provided by the certificates issued by the competent authorities. In addition to this standard, the FIPS 140 standard has been created, which specifies the requirements of cryptographic modules specifically and is used for the approval and verification of these modules. This standard is used to determine the reliability of cryptographic modules. In this thesis, we first define these standards and how the evaluation process in accordance with them takes place in the world and how they should be implemented in Turkey. Then, we discuss the vulnerabilities of the AES-GCM algorithm in order to prevent the vulnerabilities of the cryptographic algorithms used in the cryptographic algorithm verification process, which is a part of the cryptographic module verification process, and talk about alternative AES modes. Finally, we complete the thesis by talking about test vectors that help us detect these vulnerabilities.

Author

Dr. Cansu Yener

How to Cite

Cansu Yener (Master Thesis). FIPS 140 ve ISO/IEC 15408'e göre şifreleme modülleridoğrulama süreci, 2020, Middle East Technical University.

Keywords

License

Tüm Hakları Saklıdır

This work is shared under the specified license terms.

More theses from Middle East Technical University