Introduction
The DBMS-iTC is publishing Public Review Draft 1 of the full DBMS module set for general public comment. Version 0.5 includes the DBMS Cryptographic Functions Module, the DBMS in the Cloud Module, the DBMS Database-as-a-Service Module, their Supporting Documents, and the three PP-Configurations that compose those modules with the DBMS Base PP. The deployment-oriented review is organized as two complete families: Crypto + Cloud and Crypto + DBaaS. The Crypto Module formally consumes CCDB-018 Catalogue components and provides General-Purpose and optional Enterprise Enhanced cryptographic use cases. Because the companion Catalogue Evaluation Methods were not publicly available at the publication date, the Crypto SD also proposes a transitional mechanism for using Certification Body-recognized CAVP, CMVP, or equivalent validation results as evidence for covered algorithm-correctness objectives. This draft additionally offers post-quantum selections in anticipation of corresponding Catalogue collateral - ML-DSA signature verification and role-specific ML-KEM key generation, encapsulation, and decapsulation - relying on the same transitional mechanism for FIPS 203 and FIPS 204 algorithm correctness; see the review questions below.
Submit specific PP-Module, Supporting Document, or PP-Configuration comments through the DBMS issue-template chooser. Use DBMS-iTC Discussions for cross-document questions or proposals that need community input first. The ../../docs/public-review-process.html[participation tutorial] explains both paths.
Review Status
- Publication Date
-
30 June 2026
- Last Revised
-
20 July 2026 (Version 0.5: priority-finding closure, role-specific ML-KEM model, complete review-set refresh)
- End of Comment Period
-
To be announced
- Review Phase
-
Public Review Draft 1
Review Set Structure
All Version 0.5 module artifacts are included in the same review release. Reviewers should assess the set as two deployment-oriented compositions: Crypto + Cloud for tenant-operated cloud deployments, and Crypto + DBaaS for provider-operated managed database services. The Crypto Module and SD participate in both families. The Crypto-only PP-Configuration remains in the package as the foundational Base cPP + Crypto composition.
| Review family | Module documents | PP-Configuration |
|---|---|---|
Crypto + Cloud |
Cryptographic Functions Module and SD; DBMS in the Cloud Module and SD |
Base cPP + Crypto + Cloud |
Crypto + DBaaS |
Cryptographic Functions Module and SD; Database-as-a-Service Module and SD |
Base cPP + Crypto + DBaaS |
Module Documents for Review
| Title | Version | Review Family | Links |
|---|---|---|---|
collaborative PP-Module for DBMS Cryptographic Functions |
0.5 |
Both review families |
|
Supporting Document: Evaluation Activities for collaborative PP-Module for DBMS Cryptographic Functions |
0.5 |
Both review families |
|
collaborative PP-Module for DBMS in the Cloud |
0.5 |
Crypto + Cloud |
|
Supporting Document: Evaluation Activities for collaborative PP-Module for DBMS in the Cloud |
0.5 |
Crypto + Cloud |
|
collaborative PP-Module for Database-as-a-Service (DBaaS) |
0.5 |
Crypto + DBaaS |
|
Supporting Document: Evaluation Activities for collaborative PP-Module for Database-as-a-Service (DBaaS) |
0.5 |
Crypto + DBaaS |
PP-Configurations for Review
| Title | Version | Role in Review Set | Links |
|---|---|---|---|
PP-Configuration for cPP_DBMS and DBMS Cryptographic Functions Module |
0.5 |
Crypto foundation used by both families |
|
PP-Configuration for cPP_DBMS, DBMS in the Cloud Module, and DBMS Cryptographic Functions Module |
0.5 |
Crypto + Cloud |
|
PP-Configuration for cPP_DBMS, DBMS Database-as-a-Service Module, and DBMS Cryptographic Functions Module |
0.5 |
Crypto + DBaaS |
Base PP
These modules and PP-Configurations are designed for use with the DBMS Base PP Version 2.0. The DBMS Version 2.0 public review draft is available at DBMS Version 2.0 Public Review Draft 1.
Interactive Review Supplement
The DBMS Module Review Supplement provides two linked views of the review set:
-
A Reader’s Guide that explains the division of responsibility among the Base cPP, Crypto Module, and the alternative Cloud and DBaaS deployment overlays; walks the selected PP-Configuration through the major security-architecture concerns; and provides an
ADV_ARC.1completeness checklist. -
A Requirements Explorer that traces requirements, open operations, selection and dependency triggers, Supporting Document activities, and tests back to their owning artifacts.
The supplement is a non-normative review aid. The PP, PP-Modules, PP-Configurations, and Supporting Documents remain the authoritative sources.
Review Focus
Reviewers are encouraged to focus on:
-
Whether the DBMS Cryptographic Functions Module correctly owns the shared DBMS cryptographic requirements, including
FDP_DIT_EXT.1. -
Whether the Crypto Module clearly distinguishes Catalogue-derived SFRs, ECDs, dependencies, and Evaluation Activities from DBMS-iTC-originated integration requirements.
-
Whether the explicit Master Key protection selection in
FCS_CKM_EXT.1.2cleanly and testably separates TOE-enforced cryptographic protection, non-exportable hardware-backed storage, and transient-only handling from supporting operational-environment storage protection. -
Whether the normative Crypto Module audit-event refinement captures the required key-lifecycle and protected-channel events without permitting secret key material or protected payloads in audit records.
-
Whether the Crypto SD’s transitional validation-evidence mechanism provides sufficient implementation, operating-environment, capability-coverage, residual-testing, and reporting controls without treating CAVP or CMVP as a substitute for DBMS integration activities.
-
Whether the optional Enterprise Enhanced use case appropriately constrains only the in-scope Catalogue selections needed for FIPS 140-3, NIAP, and CNSA 2.0 alignment.
-
Whether symmetric key encryption without an integrity mechanism (
FCS_COP.1/SKC) should remain a permitted DEK-protection option inFCS_CKM_EXT.1.2under the General-Purpose use case, or whether key wrapping or authenticated encryption should be required for all conforming TOEs. The Enterprise Enhanced use case already requires key wrapping or authenticated encryption for stored DEKs. -
Whether the transitional use of CMVP (FIPS 140-3) module-validation evidence for the RBG self-test and failure-behavior iterations (
FPT_TST.1/RBG,FPT_FLS.1/RBG), pending publication of the Catalogue Evaluation Methods, provides sufficient assurance under appropriate Certification Body control. -
Whether the Crypto Module should offer ML-DSA signature verification (
FCS_COP.1/SigVer) and role-specific ML-KEM KeyGen, encapsulation, and decapsulation (FCS_CKM.1/KEMandFCS_COP.1/KeyEncap) in anticipation of corresponding CCDB Cryptographic Catalogue collateral, relying on the transitional CAVP evidence mechanism for FIPS 203 and FIPS 204 algorithm correctness until the corresponding Catalogue entries and Evaluation Methods are available. -
Whether the General-Purpose use case should retain the full FIPS 203/204 parameter-set families (ML-DSA-44/65/87, ML-KEM-512/768/1024), with the Enterprise Enhanced use case constraining selections to ML-DSA-87 and ML-KEM-1024, or whether only the CNSA 2.0 parameter sets should be offered, as in the AppSW cPP Version 2 approach.
-
Whether the DBMS in the Cloud Module contains only cloud-specific refinements, integration checks, and deployment-channel mapping.
-
Whether the Cloud SD’s stable activity-group identifiers and complete CEM mapping provide sufficient traceability for every FAU, FIA, FMT, FPT, FDP, and SAR Evaluation Activity.
-
Whether the DBaaS Module’s tenant-isolation, customer-controlled-key, provider-role-separation, trusted-update, service-event, and managed-service evidence models are complete and testable for publication alongside the Crypto + Cloud family.
-
Whether the PP-Configurations correctly compose the Base PP and required modules without creating contradictory conformance paths.