commoncriteria / operatingsystem

Protection Profile for Operating Systems
The Unlicense
9 stars 6 forks source link

Crypto DAR != Crypto DIT #56

Closed kgal closed 9 years ago

kgal commented 9 years ago

"We think that it may be clearer for all the modes to be in the selection (and they have to select all that they support). The other issue is that C doesn't want CTR for DAR functionality, but that doesn't mean that it wouldn't make sense in some other scenario. So, maybe we need to talk about separating DAR encryption/decryption from the general requirement? "

ajcousi commented 9 years ago

I thought DAR was being handled in another PP? So can't we just ignore it here and concentrate on DIT?

kgal commented 9 years ago

Yes to the former. I don't know for the latter. Our requirement says "The OS shall perform encryption/decryption in accordance with a specified cryptographic algorithm." It's not making a distinction between DAR and DIT. It probably should. But are there enc/dec modes for DAR that the OS should provide?