New NIST document offers guidance in cryptographic key generation

December 13, 2012
NIST's Special Publication 800-133 will help people find the specifics on how to generate cryptographic keys, used in secure data transmission and storage of sensitive information. Credit: Talbott/NIST

(Phys.org)—Protecting sensitive electronic information in different situations requires different types of cryptographic algorithms, but ultimately they all depend on keys, the cryptographic equivalent of a password. A new publication from the National Institute of Standards and Technology (NIST) aims to help people secure their data with good keys no matter which algorithm they choose.

NIST Special Publication (SP) 800-133 offers guidance on generating the that are needed to employ algorithms that provide confidentiality and integrity protection for data. Even if adversaries know what algorithm is used, they cannot gain access to the data unless they also have the proper key. SP 800-133 will be helpful to anyone who needs the specifics on how to generate these keys successfully, whether for secure or storage of sensitive information, to give two examples of their use.

SP 800-133 is primarily a high-level document that refers readers to other documents that contain details on generating the various types of keys. However, it does offer specific details for one type of key generation: the keys used in symmetric-key algorithms, in which the same key is used, for example, to both encrypt and decrypt data. Symmetric-key algorithms operate quickly, and the keys must be kept secret. These algorithms are used to protect sensitive information, including other keys, for which the algorithm is iterated as many times as needed to protect the information.

Another type of algorithm—an asymmetric-key algorithm—uses two keys: a that may be known by anyone, and a that is known by only one party and must be kept secret. Asymmetric-key algorithms are generally slower than symmetric-key algorithms and are used in cases where only a single operation of the algorithm is required, such as the generation of a or the encryption of a key to be used later with a symmetric-key algorithm. Details on the generation of keys for asymmetric-key algorithms are not offered in SP 800-133, but the document references others containing the key generation specifications.

The publication is part of a group of documents concerning cryptographic key management, namely SP 800-57 (parts one, two and three), SP 800-130, SP 800-152, and the Federal Information Processing Standard (FIPS) 186 Digital Signature Standard.

Explore further: Improving the security of Internet exchanges

More information: csrc.nist.gov/publications/nistpubs/800-133/sp800_133.pdf

Related Stories

Improving the security of Internet exchanges

March 20, 2009

(PhysOrg.com) -- TLS is the main protocol used today to secure exchanges over the Internet. The protocol has been subject to attacks in recent years, resulting in identity theft and data tampering. To address these problems, ...

Secure radio signal for central locking

February 1, 2010

(PhysOrg.com) -- Remote central locking is among the most convenient aspects of modern motoring. Transmission of the radio signal that activates the system is not particularly secure, however. A new encryption technique increases ...

Build safety into the very beginning of the computer system

April 29, 2011

A new publication from the National Institute of Standards and Technology (NIST) provides guidelines to secure the earliest stages of the computer boot process. Commonly known as the Basic Input/Output System (BIOS), this ...

NIST proposes update to digital signature standard

April 18, 2012

The National Institute of Standards and Technology (NIST) has announced proposed changes to a standard that specifies how to implement digital signatures, which can be used to ensure the integrity of electronic documents, ...

Mining ' and Minding ' Her Ps and Qs

August 10, 2012

(Phys.org) -- Each time you connect to a secure website (say a bank’s website), you begin by downloading a certificate published by the site, which asserts that its Web address is legitimate. It also contains a public ...

Recommended for you

Tech leaders warn over 'killer robots' (Update)

July 28, 2015

A group of top tech leaders, including British scientist Stephen Hawking and Apple co-founder Steve Wozniak, on Tuesday issued a stern warning against the development of so-called killer robots.

Cellphones can steal data from 'air-gapped computers'

July 28, 2015

Researchers at the Ben-Gurion University of the Negev (BGU) Cyber Security Research Center have discovered that virtually any cellphone infected with a malicious code can use GSM phone frequencies to steal critical information ...

Where is solar power headed?

July 22, 2015

Most experts agree that to have a shot at curbing the worst impacts of climate change, we need to extricate our society from fossil fuels and ramp up our use of renewable energy.

0 comments

Please sign in to add a comment. Registration is free, and takes less than a minute. Read more

Click here to reset your password.
Sign in to get notified via email when new comments are made.