APPENDIX B (NORMATIVE)
APPROVED CRYPTOGRAPHIC
ALGORITHMS AND PROTOCOLS
All Cryptographic algorithms recommended in this Appendix B are valid for one year after the date of issue of this
manual. The GIAM shall recommend updates or alternatives to this algorithms as and when necessary. These
algorithms and protocols are used for encryption, digital signatures, random number generation, key agreement, key
transportation, key wrapping, deriving additional keys from a cryptographic key, hash numbers, MAC, etc.
Symmetric Key/Private Key:
Cryptographic functions that use a symmetric key cipher (sometimes referred to as private key encryption) employing a
shared secret key must adopt any of the following specifications.
Algorithm
Name
References
Approved Use
Required Key
Length
AES
Advanced Encryption Standard block cipher
based on the “Rijndael” algorithm [AES]
General Data
Encryption
256-bit keys
TDES /3DES
Triple Data Encryption Standard (or Triple DES)
block cipher [SP800-67]
General Data
Encryption
three unique 56-bit
keys
Note: AES SHOULD be used unless this is not technically possible. TDES usage should be limited to systems not
supporting AES.
Asymmetric Key/Public Key:
Cryptographic functions that use asymmetric key ciphers (also known as public key encryption) that employ a pair of
cryptographic keys consisting of one public key and one private key must adhere to the following specifications:
Algorithm
Name
References
Approved Use
Required Key
Length
RSA
“Rivest-Shamir-Adleman” algorithm for publickey cryptography [RSA]
Digital Signatures,
Transport of
encryption
1024-bit keys
DSA
Digital Signature Algorithm [FIP186-2]
Digital Signatures
1024-bit keys
Note: 1024 bit keys are to be replaced with 2048 bit keys for RSA and lpl>=2048 bits & lql>=224 bits for DSA by
2013. Use of 1024 bit keys will be discontinued after 2013.
NATIONAL INFORMATION ASSURANCE MANUAL
54