The FIPS 140-3 standard took over from FIPS 140-2 on September 22, 2019. FIPS 140-3 validation started in September 2020. As Bitcoin and blockchains gain popularity, cryptocurrencies and digital assets are becoming increasingly common in finance. It’s crucial for systems dealing with digital assets to be safe. This standard sets out security rules for Cactus Custody products. It includes our design and how we use them to ensure that our business customers can confidently use digital currencies like Bitcoin in a regulated economy, knowing their assets are always secure.

What is FIPS 140-3?

The Federal Information Processing Standard (FIPS) 140-3 is a set of rules created by the U.S. government to ensure that cryptographic tools are effective and secure. It’s like a guidebook that teaches you how to design, build, and use these tools safely.

The National Institute of Standards and Technology (NIST) and the Communications Security Establishment (CSE) developed FIPS 140-3 to protect important but not classified information. It includes stricter authentication for modules, better physical security measures, and improved ways to manage credentials. It also allows organisations to adapt security policies to their specific needs flexibly. These rules cover physical security, key management, identity verification, and other security measures.

Companies and organisations need to test their cryptographic tools to make sure they meet the standards set by FIPS 140-3. This certification is crucial for securing sensitive information and preventing unauthorised access or tampering.

FIPS 140-3 replaces FIPS 140-2 and establishes a new federal security standard for cryptographic tools. The updated standard aligns with the rules outlined in ISO/IEC 19790:2012(E). It includes changes to the additional information the Cryptographic Module Validation Program (CMVP) allows, which certifies these tools.

What are the Different Levels of FIPS 140-3?

The National Institute of Standards and Technology (NIST) created FIPS 140-3 to ensure that cryptographic devices and modules used in secure IT systems are safe and reliable. This third version of this standard has four levels.

Level 1:

This level requires tools that are good enough for regular use and algorithms that outside experts have tested.

Level 2:

At this level, there’s an extra requirement for authentication based on roles and evidence of physical tampering.

Level 3:

Here, there are more requirements for verifying identities and ensuring the module can’t be tampered with physically. Also, the ways “critical security parameters” enter and exit the module must be separated physically or logically. Only encrypted private keys can be exchanged. The module must also sense and react to extreme voltage or temperature changes (environmental failure protection or EFP) or undergo ecological failure tests.

Level 4:

This level steps up physical security, requiring active detection of tampering. FIPS 140-3 is becoming more critical as businesses and organisations want to protect their IT systems worldwide. 

If it detects specific environmental attacks, it erases the device’s contents. EFP, fault injection prevention, and multi-factor authentication are all needed.

What’s New in FIPS 140-3 Compared to FIPS 140-2?

FIPS 140-3 is the latest U.S. government standard for validating computer security in cryptographic modules. It’s a step forward from FIPS 140-2 and comes with several improvements, including:

Mode of Operation Indicator: All modules must now report their approved mode of operation, ensuring transparency in their functioning.

Stricter Zeroization Requirements: Critical Security Parameters (CSPs) must be thoroughly cleared for added security.

Authentication Complexity: The module must enforce authentication data rather than relying on procedural methods, making it more secure.

Enhanced Physical Security: At Level 3, modules must detect and react to environmental changes like voltage or temperature fluctuations. Level 4 requires protection against fault injection.

Multi-Factor Authentication (MFA): Level 4 now requires MFA, adding an extra layer of security.

Assurance Requirements: New requirements ensure better security practices during the module’s development lifecycle, such as developer testing and using security diagnostic tools.

Non-Invasive Security: This optional requirement offers guidance on testing against side-channel attacks, enhancing overall security measures.

These FIPS 140-3 enhancements make cryptographic modules more secure and aligned with international standards, ensuring better protection for sensitive data and systems.

In a Nutshell…

The National Institute of Standards and Technology (NIST) in the United States has published a security standard for cryptographic modules called FIPS 140-3.

This standard sets out four levels of security requirements based on a company’s needs and the application’s purpose. FIPS-3 has broadened the scope of cryptographic protection.

Allowing certain hybrid modules to meet higher security standards could make handling important and sensitive information safer.