|
1.
|
Clear description of the referenced document:
|
|
|
|
|
2.
|
Status of approval:
|
|
|
Federal Information Processing Standard (FIPS) approved 2012-03.
|
|
3.
|
Justification for the specific reference:
|
|
|
This Recommendation | International Standard specifies an interoperable bitstream format for biomedical and general waveform signal coding and includes optional authentication-related syntax for verifying coded packets. In particular, the aust_hash_type syntax element identifies the hashing algorithm used for authentication information, and Table 619 specifies SHA-1, SHA-224, SHA-256, SHA-384 and SHA-512 as hashing algorithms, each “as specified by NIST FIPS PUB 180-4”.
A normative reference to FIPS PUB 180-4, Secure Hash Standard (SHS) is necessary because the present Recommendation | International Standard relies on externally defined SHA hash algorithms rather than defining those algorithms itself. FIPS PUB 180-4, Secure Hash Standard (SHS) specifies hash algorithms that can be used to generate digests of messages, and those digests are used to detect whether messages have been changed since the digests were generated. The NIST publication also identifies the standard as the Secure Hash Standard and specifies secure hash algorithms including SHA-1, SHA-224, SHA-256, SHA-384 and SHA-512.
The reference is technically appropriate because authentication in this Recommendation | International Standard depends on consistent interpretation and implementation of the selected SHA algorithms. By referencing FIPS PUB 180-4, Secure Hash Standard (SHS), the document ensures that encoders, decoders and verification systems apply the same externally defined hash algorithm specifications when generating or verifying authentication information. This supports interoperability without duplicating cryptographic algorithm definitions in the waveform coding specification.
Reason incorporation of the full text is inappropriate:
Incorporating the full text of FIPS PUB 180-4, Secure Hash Standard (SHS) into this Recommendation | International Standard would be inappropriate because the present document only needs to identify the applicable SHA algorithms for authentication-related syntax. It does not need to reproduce the full hash algorithm specification, including the detailed algorithm definitions, preprocessing, computation steps, constants, explanatory material and publication framework contained in the NIST standard.
Full-text incorporation would also obscure the scope of this Recommendation | International Standard. The main subject of the document is the coding, transmission and storage of biomedical and general waveform signals, while FIPS PUB 180-4, Secure Hash Standard (SHS) is a separate cryptographic standard specifying hash algorithms for message digests. Referencing the NIST document preserves the proper separation between the waveform coding specification and the authoritative cryptographic algorithm specification.
Incorporation would create avoidable maintenance and consistency risks. The NIST CSRC record indicates that the August 2015 publication supersedes the March 2012 version and includes a planning note that NIST has decided to revise FIPS 180-4. Reproducing the full text in this Recommendation | International Standard could therefore result in a duplicated version that diverges from the authoritative NIST publication or from later revisions, whereas reference by citation enables implementers to consult the controlling source directly.
Conclusion:
The reference to FIPS PUB 180-4, Secure Hash Standard (SHS) is justified because authentication-related syntax in this Recommendation | International Standard uses SHA hash algorithms that are specified by that NIST standard. Incorporation of the full text is inappropriate because the Recommendation | International Standard only needs to rely on the SHA algorithm definitions by reference, while the complete cryptographic specification should remain with the authoritative NIST publication to avoid duplication, scope expansion and maintenance divergence.
|
|
4.
|
Current information, if any, about IPR issues:
|
|
|
Some information may be available in the NIST Patents Database that can be accessed through http://patapsco.nist.gov/ts/220/sharedpatent/index.cfm
|
|
5.
|
Other useful information describing the "Quality" of the document:
|
|
|
This standard specifies hash algorithms that can be used to generate digests of messages. The digests are used to detect whether messages have been changed since the digests were generated. This NIST document has been produced by Computer Security Division's (CSD) Security Technology Group of NIST has a subgroup that deals specifically with Cryptographic Technology Standards and Guidance (CTSG). CTSG is involved in the development, maintenance, and promotion of a number of standards and guidance that cover a wide range of cryptographic technology.
NIST has long term technical experience in dealing with cryptographic matters. The document has been publicly and internally reviewed before publication.
|
|
6.
|
The degree of stability or maturity of the document:
|
|
|
Published in March 2012. This Standard supersedes FIPS 180-3, which had already superseded FIPS 180-2. For the relationship between FIPS 180-4 and FIPS 140-2, see IG 1.10 of the Implementation Guidance for FIPS PUB 140-2 and the Cryptographic Module Validation Program at http://csrc.nist.gov/groups/STM/cmvp.
|
|
7.
|
Relationship with other existing or emerging documents:
|
|
|
NIST is actively involved in standardization of cryptographic techniques. The crypto tools are of wide general applicability (see e.g. DES, AES, modes of operation and guidelines). NIST continues its research and standardization in the area of modes of operation.
Guidance regarding the testing and validation to FIPS 180-4 and its relationship to FIPS 140-2 can be found in IG 1.10 of the Implementation Guidance for FIPS PUB 140-2 and the Cryptographic Module Validation Program at http://csrc.nist.gov/groups/STM/cmvp.
|
|
8.
|
Any explicit references within that referenced document should also be listed:
|
|
|
APPENDIX B: REFERENCES/
[FIPS 180-3] NIST, Federal Information Processing Standards Publication 180-3, Secure Hash Standards (SHS) , October 2008. /
[SP 800-57] NIST Special Publication (SP) 800-57, Part 1, Recommendation for Key Management: General , (Draft) May 2011. /
[SP 800-107] NIST Special Publication (SP) 800-107, Recommendation for Applications Using Approved Hash Algorithms , (Revised), (Draft) September 2011.
|
|
9.
|
Qualification of
NIST:
|
|
|
Qualification of NIST: NIST is recognized under the provisions of ITU-T Recommendation A.5. Qualifying information is on file in TSB.
|
|
10.
|
Other (for any supplementary information):
|
|
|
N/A
|