{"id":17641,"date":"2014-04-23T00:49:27","date_gmt":"2014-04-23T04:49:27","guid":{"rendered":"http:\/\/www.opensource.im\/?p=17641"},"modified":"2014-04-23T00:49:27","modified_gmt":"2014-04-23T04:49:27","slug":"nist-removes-cryptography-algorithm-from-random-number-generator-recommendations","status":"publish","type":"post","link":"https:\/\/euvolution.com\/open-source-convergence\/cryptography\/nist-removes-cryptography-algorithm-from-random-number-generator-recommendations.php","title":{"rendered":"NIST removes cryptography algorithm from random number generator recommendations"},"content":{"rendered":"<p><p>15 hours ago by Jennifer Huergo            <\/p>\n<p>    Following a public comment period and review, the National    Institute of Standards and Technology (NIST) has removed a    cryptographic algorithm from its draft guidance on random    number generators. Before implementing the change, NIST is    requesting final public comments on the revised document,    Recommendation    for Random Number Generation Using Deterministic Random Bit    Generators (NIST Special Publication 800-90A, Rev. 1).  <\/p>\n<p>    The revised document retains three of the four previously    available options for generating pseudorandom bits needed to    create secure cryptographic keys for encrypting data. It omits    an algorithm known as Dual_EC_DRBG, or Dual Elliptic Curve    Deterministic Random Bit Generator. NIST recommends that    current users of Dual_EC_DRBG transition to one of the three    remaining approved algorithms as quickly as possible.  <\/p>\n<p>    In September 2013, news reports prompted public concern about    the trustworthiness of Dual_EC_DRBG. As a result, NIST    immediately recommended against the use of the algorithm and    reissued SP 800-90A for public comment.  <\/p>\n<p>    Some commenters expressed concerns that the algorithm contains    a weakness that would allow attackers to figure out the secret    cryptographic keys and defeat the protections provided by those    keys. Based on its own evaluation, and in response to the lack    of public confidence in the algorithm, NIST removed    Dual_EC_DRBG from the Rev. 1 document.  <\/p>\n<p>    The revised SP 800-90A is available at csrc.nist.gov\/news_events\/index.html#apr21 along    with instructions for submitting comments. The public comment    period closes on May 23, 2014. NIST will take those comments    into consideration in making any revisions to SP 800-90A.  <\/p>\n<p>    NIST recommends that vendors currently using Dual_EC_DRBG who    want to remain in compliance with federal guidance, and who    have not yet made the previously recommended changes to their    cryptographic modules, should select an alternative algorithm    and not wait for further revision of the Rev. 1 document.  <\/p>\n<p>    NIST advises federal agencies and other buyers of cryptographic    products to ask vendors if their cryptographic modules rely on    Dual_EC_DRBG, and if so, to ask their vendors to reconfigure    those products to use alternative algorithms.  <\/p>\n<p>    A list of cryptographic modules that include Dual_EC_DRBG can    be found at    <a href=\"http:\/\/csrc.nist.gov\/groups\/STM\/cavp\/documents\/drbg\/drbgval.html\" rel=\"nofollow\">http:\/\/csrc.nist.gov\/groups\/STM\/cavp\/documents\/drbg\/drbgval.html<\/a>.    Most of these modules implement more than one random number    generator. In some cases, the Dual_EC_DRBG algorithm may be    listed as included in a product, but another approved algorithm    may be used by default. If a product uses Dual_EC_DRBG as the    default random number generator, it may be possible    to reconfigure the product to use a different default algorithm.  <\/p>\n<p>    Draft versions of related guidance, 800-90 B: Recommendation    for the Entropy Sources Used for Random Bit Generation and    800-90 C: Recommendation for Random Bit Generator (RBG)    Constructions, were also released for comment in September 2013    and are still under development.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Read more from the original source:<br \/>\n<a target=\"_blank\" href=\"http:\/\/phys.org\/news317376478.html\/RS=^ADADOZpJ7N35Z4ts_3Mt5qgkyQok30-\" title=\"NIST removes cryptography algorithm from random number generator recommendations\">NIST removes cryptography algorithm from random number generator recommendations<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> 15 hours ago by Jennifer Huergo Following a public comment period and review, the National Institute of Standards and Technology (NIST) has removed a cryptographic algorithm from its draft guidance on random number generators. <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1600],"tags":[],"class_list":["post-17641","post","type-post","status-publish","format-standard","hentry","category-cryptography"],"_links":{"self":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/17641"}],"collection":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/comments?post=17641"}],"version-history":[{"count":0,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/17641\/revisions"}],"wp:attachment":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/media?parent=17641"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/categories?post=17641"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/tags?post=17641"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}