Download the Cryptlib manual

Transcript
Diffie-Hellman
305
the algorithm as having a 128 or 192-bit key, but bear in mind that only the high 7
bits of each byte are actually used as keying material.
Loading a key will return a CRYPT_ERROR_PARAM3 error if the key is a weak
key. cryptExportKey will export the correct parity-adjusted version of the key.
Triple DES has been implemented as per:
ANSI X9.17, “American National Standard, Financial Institution Key
Management (Wholesale)”, 1985.
ANSI X9.52, “Triple Data Encryption Algorithm Modes of Operation”, 1999.
FIPS 46-3, “Data Encryption Standard (DES)”, 1999.
ISO/IEC 8732:1987, “Banking — Key Management (Wholesale)”.
The triple DES modes of operation are given in:
ISO/IEC 8372:1987, “Information Technology — Modes of Operation for a 64bit Block Cipher Algorithm”.
ISO/IEC 10116:1997, “Information technology — Security techniques — Modes
of operation for an n-bit block cipher algorithm”.
The DES code has been validated against the test vectors given in:
NIST Special Publication 800-20, “Modes of Operation Validation System for the
Triple Data Encryption Algorithm”.
Diffie-Hellman
Diffie-Hellman is a key-agreement algorithm with a key size of up to 4096 bits and
has the cryptlib algorithm identifier CRYPT_ALGO_DH.
Diffie-Hellman was formerly covered by a patent in the US, this has now expired.
DH has been implemented as per:
PKCS #3, “Diffie-Hellman Key Agreement Standard”, 1991.
ANSI X9.42, “Public Key Cryptography for the Financial Services Industry —
Agreement of Symmetric Keys Using Diffie-Hellman and MQV Algorithms”,
2000.
DSA
DSA is a digital signature algorithm with a key size of up to 1024 bits and has the
cryptlib algorithm identifier CRYPT_ALGO_DSA.
DSA is covered by US patent 5,231,668, with the patent held by the US government.
This patent has been made available royalty-free to all users world-wide. The US
Department of Commerce is not aware of any other patents that would be infringed
by the DSA. US patent 4,995,082, “Method for identifying subscribers and for
generating and verifying electronic signatures in a data exchange system” (“the
Schnorr patent”) relates to the DSA algorithm but only applies to a very restricted set
of smart-card based applications and does not affect the DSA implementation in
cryptlib.
DSA has been implemented as per:
ANSI X9.30-1, “American National Standard, Public-Key Cryptography Using
Irreversible Algorithms for the Financial Services Industry”, 1993.
FIPS PUB 186, “Digital Signature Standard”, 1994.
ECDSA
ECDSA is a digital signature algorithm with a key size of up to 521 bits and has the
cryptlib algorithm identifier CRYPT_ALGO_ECDSA.