Choosing algorithms to standardise
Chris J. Mitchell · 2012
The developers of the ISO/IEC standard on encryption, ISO/IEC 18033, are facing a dilemma. To maximise interoperability and make life as simple as possible for developers, the smallest possible number of algorithms should be standardised; however, despite this, there seems to be an inexorable growth in the number of standardised algorithms. We put this problem into historical context, and review efforts to devise ways of restricting the numbers of standardised algorithms dating back to the beginning of the development of ISO/IEC 18033. We then consider how and why these efforts have proved inadequate, leading to an almost uncontrollably large number of standardised algorithms. Finally, we discuss recent efforts to address this situation, which appear to have ramifications not only for ISO/IEC but for almost any body seeking to standardise a set of general purpose techniques. 1 1