Mechanisms and protocols
Primitives, constructions, protocols and declared parameters are checked against the cryptographic criteria set out in CCN-STIC 221.
CCN-STIC 2100 defines how to verify that cryptography implemented in a product uses mechanisms accepted by the CCN, operates correctly and avoids implementation flaws that could expose sensitive information.
CCN-STIC 2100 sets out the Cryptographic Mechanisms Evaluation Methodology (MEMeC). It provides a common method for evaluating cryptographic implementations included in products following Common Criteria, LINCE or STIC certification.
The MEMeC evaluation is performed separately and in parallel with the main process. It must not be confused with MEC, the cryptographic evaluation module integrated into the LINCE methodology.
The evaluation examines the product's actual implementation. Naming a recognised algorithm is not enough: the mechanism, its parameters, how it is called and the controls protecting keys and other sensitive parameters must be assessed.
CCN-STIC 221 lists the cryptographic mechanisms and parameters accepted by the CCN. CCN-STIC 2100 turns those criteria into evaluation tasks that verify how they are implemented and parameterised in the product.
Technical scope
The methodology combines document review, implementation analysis and testing. The exact scope depends on the assigned level, but the work is organised around four areas.
Primitives, constructions, protocols and declared parameters are checked against the cryptographic criteria set out in CCN-STIC 221.
Test vectors are used to confirm that each mechanism returns the expected results with the evaluated parameterisation.
The assessment looks for common pitfalls that could affect the mechanism or expose data, keys or other security parameters.
Depending on the level, self-tests, sensitive parameter management and protections against implementation attacks are also reviewed.
Evaluation process
Section 1.5 of CCN-STIC 2100 sets out how the evaluation proceeds once the vendor inputs have been received. The work is tailored to CL1, CL2 or CL3 and to the mechanisms implemented by the product.
1. Inputs and scope
The questionnaires, cryptographic inventory, version, interfaces and available evidence are reviewed.
2. Applicable tasks
Mandatory tasks and those that depend on functionality present in the TOE are selected.
3. Technical evaluation
Requirements, mechanisms and parameters, conformity, self-tests and implementation pitfalls are assessed.
4. Results documentation
The performed tasks, evidence, results, non-conformities and remediation verification are documented.
The outcome maintains traceability between the performed tasks, reviewed evidence, tests and remediation verified during the evaluation.
CCN-STIC 2100 defines three increasing assurance levels. The selected level determines the depth of analysis and the evidence the vendor must provide.
Level 1
Checks mechanisms and protocols accepted by the CCN and runs conformity tests. A reduced vendor questionnaire is available for this level.
Level 2
Covers every task in the methodology. For sensitive parameter management, it requires evidence of secure zeroisation.
Level 3
Applies all tasks and requires evidence covering the complete lifecycle of sensitive parameters, from generation through destruction.
Preparation matters because the laboratory needs to reach each mechanism and reproduce the tests using a known configuration. CCN-STIC 2100 identifies eight input groups that should be prepared as a coherent set.
We analyse the product's cryptography, establish the applicable scope and level, work with your team to prepare the documentation and test interfaces, and perform the checks defined by MEMeC.
We handle the evaluation so your team can stay focused on the product.
View MEMeC evaluation serviceRelated
Explains the LINCE methodology and its MEC module, which is distinct from the MEMeC evaluation defined in CCN-STIC 2100.
Read CCN-STIC 2002 →Places evaluations within the CPSTIC qualification and inclusion procedures.
Read CCN-STIC 106 →This analysis is based on CCN-STIC 2100 v1.3.3 and its annexes. You can compare it with the complete version published by the Spanish National Cryptologic Centre.
Consult CCN-STIC 2100 →We review the implementation, applicable level and required evidence to prepare and perform the MEMeC evaluation.