商品描述
This book provides a comprehensive, practice-driven guide to understanding and implementing secure cryptographic modules. It bridges newly published international standards--ISO/IEC 19790:2025 and ISO/IEC 24759:2025--with decades of hands-on validation experience from astec's globally respected testing laboratory. Designed to demystify cryptographic compliance, it serves developers, security professionals, researchers, and advanced-level students in computer science.
It explores the evolution and current practices of the Cryptographic Module Validation Program (CMVP), jointly managed by NIST and Canada's CCCS, highlighting its foundational role in securing global digital infrastructure. Topics include technical requirements, testing methodologies, real-world case studies, and future developments such as post-quantum cryptography and validation automation through NCCoE's ACMVP.
This book also highlights the collaborative ecosystem supporting cryptographic assurance--focusing on the CMUF, ICMC, and atsec's FIPS 'n' Chips bootcamp. These forums help shape standards, foster innovation, and strengthen community. By connecting theory with implementation and policy with practice, this book delivers actionable insights at a critical time for modern cryptography.
商品描述(中文翻譯)
本書提供了一個全面且以實踐為導向的指南,幫助讀者理解和實施安全的加密模組。它將新發布的國際標準——ISO/IEC 19790:2025 和 ISO/IEC 24759:2025——與來自於astec全球知名測試實驗室的數十年實務驗證經驗相結合。旨在揭開加密合規的神秘面紗,為開發人員、安全專業人士、研究人員以及計算機科學的高級學生提供服務。
本書探討了加密模組驗證計畫(CMVP)的演變及當前實踐,該計畫由NIST和加拿大的CCCS共同管理,強調其在保護全球數位基礎設施中的基礎性角色。主題包括技術要求、測試方法、實際案例研究,以及未來發展,如後量子加密和通過NCCoE的ACMVP進行的驗證自動化。
本書還強調了支持加密保障的協作生態系統,重點介紹CMUF、ICMC以及atsec的FIPS 'n' Chips訓練營。這些論壇有助於塑造標準、促進創新並加強社群。通過將理論與實施、政策與實踐相連結,本書在現代加密技術的關鍵時刻提供了可行的見解。
作者簡介
Dr. Yi Mao is a CISSP and holds a Ph.D. in Mathematical Logic (2003) and a Master's degree in Computer Science (2000) from the University of Texas at Austin. Dr. Mao is the CEO at atsec U.S. Corporation. She runs the overall U.S. branch operation, coordinates with atsec sibling branches in Europe and Asia, and supervises IT product security testing and evaluation based on standards such as FIPS and Common Criteria (CC). She is an expert member of ISO/IEC JTC1/SC27, a former CMUF to ISO WG3 Liaison Officer, CMUF Steering Committee Member, and the ICMC Program Committee Chair.
作者簡介(中文翻譯)
Dr. Yi Mao 是一位 CISSP,並於 2003 年獲得德克薩斯大學奧斯汀分校的數學邏輯博士學位,以及於 2000 年獲得計算機科學碩士學位。Mao 博士是 atsec U.S. Corporation 的執行長。她負責美國分公司的整體運營,與位於歐洲和亞洲的 atsec 兄弟分公司協調,並根據 FIPS 和 Common Criteria (CC) 等標準監督 IT 產品的安全測試和評估。她是 ISO/IEC JTC1/SC27 的專家成員,曾擔任 ISO WG3 的 CMUF 聯絡官、CMUF 指導委員會成員,以及 ICMC 程序委員會主席。