Ledger continues its security certification program with Ledger Nano X

2019-12-12 16:59

The Ledger Nano X receives CSPN (First Level Security Certificate) certification issued by ANSSI (National Agency for Information Systems Security). 

Following the Ledger Nano S announcement a few months ago, this makes both Ledger Nano X and S the only hardware wallets to be certified, according to the security requirements specified in the CSPN security certification scheme.

At Ledger, we believe security is paramount, and while anyone can claim to have a secure product, it means much more coming from a trusted third party. This is an important milestone for Ledger in our effort to certify all our B2C and B2B  products.

The CSPN Certification scheme was established in 2008 and is a process for undergoing evaluation across several categories, including firewall, identification, authentication and access, secure communications and embedded software. To achieve certification, we selected one of ANSSI’s accredited laboratories who put the product through multiple attack scenarios to challenge its security.

An External Assessment

This certification serves as an external, third-party confirmation that Ledger’s security is industry-leading. This external and independent assessment further validates the company’s commitment to industry-leading security.

« The efforts performed by Ledger to deliver state-of-the-art products to enhance the security level of the whole hardware wallet ecosystem increase customers’ trust. »

Ledger constantly looks to enhance the security of its products, leveraging both external security researchers in its Bounty Program, as well as its industry-leading, in-house Attack Lab, the Ledger Donjon. Ledger has developed a robust custom Operating System, namely BOLOS and crypto-asset apps run on top of this secure hardware. It’s this combination of software and hardware that brings the highest level of security to each of the company’s products.

What CSPN Certifies

The following core security functions embedded in the Ledger Nano X are covered by the CSPN Certificate:

True Random Number Generator:

Hardware wallets rely on the security of a “random generated number” to generate your wallet’s private keys securely. To be aligned with the CSPN security evaluation scheme, Ledger strictly complies with security rules defined in the Security General Referential. In short, the Random Number generated by the Secure Hardware is then fully post-processed by Ledger through BOLOS. It is Ledger’s implementation that makes your hardware wallet unique related to the seed.

Root of Trust:

This security function ensures the end-user that their Nano X has been issued by Ledger. This feature can appear basic, but it is vital as it supports the security model and prevents attacks. A Root of Trust has been put in place by Ledger, acting as the Certification Authority, to ensure the user’s device is genuine. This genuineness is based on a mutual authentication between the Ledger Nano X and Ledger’s Secure Server — this ensures that it’s not possible to create a counterfeited and possibly backdoored device.  

End-User Verification:

This security feature is the Personal Identification Number (PIN) that the End-User must enter correctly before accessing all services provided by the Ledger Nano X. Having an End-User Verification to ensure only the genuine Ledger Nano X holder can access their hardware wallet is a good start, but having a robust and secure implementation of this PIN verification is even safer.

Post-Issuance Capability over a Secure Channel:

On one hand, the Post-Issuance Capability is useful: Ledger can not only add new features to increase the security level of the product, but also reinforce it.
When designing the Ledger Nano X, Ledger ensured implementing this security feature. For instance, this post-issuance capability is only available after a successful mutual authentication is performed.

Learn more here.

Similar to Notcoin - Blum - Airdrops In 2024

origin »

Quantum Resistant Ledger (QRL) íà Currencies.ru

$ 0 (+0.00%)
Îáúåì 24H $0
Èçìåíåèÿ 24h: 0.00 %, 7d: 0.00 %
Cåãîäíÿ L: $0 - H: $0.307
Êàïèòàëèçàöèÿ $0 Rank 99999
Öåíà â ÷àñ íîâîñòè $ 0.1846 (-100%)

ledger security nano certification cspn only both

ledger security → Ðåçóëüòàòîâ: 126


Ôîòî:

Governance, Part 2: Plutocracy Is Still Bad

Coin holder voting, both for governance of technical features, and for more extensive use cases like deciding who runs validator nodes and who receives money from development bounty funds, is unfortunately continuing to be popular, and so it seems worthwhile for me to write another post explaining why I (and Vlad Zamfir and others) do not consider it wise for Ethereum (or really, any base-layer blockchain) to start adopting these kinds of mechanisms in a tightly coupled form in any significant way.

2018-7-21 23:03


Ôîòî:

UK Urged To Name Chief Blockchain Officer

A British politician has called for the creation of a Chief Blockchain Officer to oversee the implementation of Distributed Ledger Technology (DLT) in the UK Government. In a research paper, the Conservative Member for Walsall North, Eddie Hughes, argued blockchain would lead to greater efficiency and security in the running of government departments, potentially leading […] The post UK Urged To Name Chief Blockchain Officer appeared first on Crypto Briefing.

2018-7-18 20:58


Ôîòî:

The Genesis Files: With Bit Gold, Szabo Was Inches Away From Inventing Bitcoin

As his Hungarian parents had fled post-war Soviet regime to settle in the United States, Nick Szabo came to call the Californian Bay area of the 1990s his home. Here, he was among the first to frequent the in-person “Cypherpunk” meetings organized by Timothy May, Eric Hughes and other founding members of the collective of cryptographers, programmers and privacy activists centered around the ’90s mailing list of the same name.

2018-7-13 17:16


Crypto Wallet Ledger Introduces Ledger Live for Desktop

In a bid to appeal to more cryptocurrency investors, hardware wallet provider Ledger announced its new offering — Ledger Live. CEO Eric Larcheveque announced the new software in a blog post, stating that the company’s mission is to: “Ensure that everyone who owns crypto assets can keep them safe, using the most advanced security technology […] Crypto Wallet Ledger Introduces Ledger Live for Desktop was originally found on [blokt] - Blockchain, Bitcoin & Cryptocurrency News.

2018-7-11 16:14


Additional Ripple Lawsuit Asserts that XRP is a Security

Distributed ledger startup Ripple is facing another class-action lawsuit tied to the legal classification of the XRP cryptocurrency. Filed by California resident David Oconer, the complaint names Ripple Labs, XRP II (Ripple’s licensed money services business), Ripple CEO Brad Garlinghouse and 25 unnamed persons affiliated with the firms as defendants. The suit claims: “Here, the

2018-7-5 22:55