Guideline for implementing cryptography in the federal government

Emma Barker, William C. Barker, A Lee · 2005

Reports on Computer Systems TechnologyThe Information Technology Laboratory (ITL) at the National Institute of Standards and Technology (NIST) promotes the U.S. economy and public welfare by providing technical leadership for the Nation's measurement and standards infrastructure.ITL develops tests, test methods, reference data, proof of concept implementations, and technical analyses to advance the development and productive use of information technology.ITL's responsibilities include the development of management, administrative, technical, and physical standards and guidelines for the cost-effective security and privacy of non-national securityrelated information in Federal information systems.This special publication 800series reports on ITL's research, guidelines, and outreach efforts in information system security, and its collaborative activities with industry, government, and academic organizations. December 2005Implementing Cryptography Chapter 2 defines the role and use of standards and describes standards organizations that are outside the Federal government.Chapter 3 describes the methods that are available for symmetric and asymmetric key cryptography.Chapter 4 describes some implementation issues (e.g., key management). Chapter 5 discusses assessments, including the Cryptographic Module Validation Program (CMVP), the Common Criteria (CC), and Certification and Accreditation (C&A).Chapter 6 describes the process of choosing the types of cryptography to be used and selecting a cryptographic method or methods to fulfill a specific requirement.There are seven appendices to the guideline: Appendix A contains an acronym list. Uses of CryptographyHistorically, cryptography was used as a tool to protect secrets.Numerous techniques have been used, including:Manual systems (e.g., simple substitution, manual codes), Mechanical devices (e.g., the World War II and Korean era M 209 device), Electro-mechanical devices (e.g., the World War II Enigma and Purple devices), and Modern electronic encryption and authentication mechanisms (e.g., Advanced Encryption Standard (AES), Digital Signature Algorithm (DSA), and Keyed Hash Message Authentication Code (HMAC)).Modern cryptography uses mathematical techniques to provide security services and relies upon two basic components: an algorithm (or cryptographic methodology) and a cryptographic key, which determines the specifics of algorithm operation.

Read the paper · More papers on PaperTik