This post is older than 2 years and might not be relevant anymore
More Info: Consider searching for newer posts

FIPS 140-2 certification

Has anyone taken the Nordic LE Secure ECDH key exchange and encryption code though FIPS 140-2 certification and what level was attained? I was tasked with getting to level 1 for our product and wanted to see where others were at with respect to the US Gov encryption standards.

Parents
  • Part of the reason we want to go for FIPS level 1 is that it's a line in the sand with respect to security. There isn't many other comprehensive standards out there and at least this one is documented and followed by the gov. Does the BLE compliance suite testing verify security when using LESC? If it does I can lobby our requirements team to just refer to the testing and then we just need your test report/results and we can check the box off. FIPS was only put out there since we are a Class 3 FDA medical device maker and the gov likes to see i's dotted and t's crossed and if we show us meeting a gov standard it's easier.

    One of my projects uses Nordic on both sides of the link so we are 100% good there. The other project needs Android on the Central side, Nordic did confirm that the phone we are using Nexus 5X supported it but Google just chimed in and said no.

Reply
  • Part of the reason we want to go for FIPS level 1 is that it's a line in the sand with respect to security. There isn't many other comprehensive standards out there and at least this one is documented and followed by the gov. Does the BLE compliance suite testing verify security when using LESC? If it does I can lobby our requirements team to just refer to the testing and then we just need your test report/results and we can check the box off. FIPS was only put out there since we are a Class 3 FDA medical device maker and the gov likes to see i's dotted and t's crossed and if we show us meeting a gov standard it's easier.

    One of my projects uses Nordic on both sides of the link so we are 100% good there. The other project needs Android on the Central side, Nordic did confirm that the phone we are using Nexus 5X supported it but Google just chimed in and said no.

Children
No Data
Related