OASIS Open Mailing List Archives  ·  All Lists  ·  pkcs11  ·  2013-08

pkcs11 — archive

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]

Proposal: CKM_SHA512_224, CKM_SHA512_256, CKM_SHA512_T


It would be odd to continue to see references in NIST documents in support of the 80 bit security. SHA-512/160 still has maximum security of 80 bits in digital signature applications (the collision resistance feature). From SP 800-131A: With the publication of SP 800-57, Part 1 in 2005, NIST announced the intent to transition from a minimum cryptographic security strength of 80 bits to a security strength of 112 bits by the end of 2010. Then the doc say that NIST feels that the deadline can be extended till 2013. These extensions won't continue forever. In addition, they are more due to the widespread use of SHA-1. One would hope that if it's possible to add support for SHA-512/160, then it should be possible to add support for SHA-256. On 08/05/2013 03:33 PM, Valerie Anne Fenwick wrote: Hi Bob - Dina wasn't asking about SHA-1, but rather SHA-512/160 - which takes as much space as the SHA-1 digest (good for retrofit into older protocols that didn't leave expansion space). Valerie On 08/ 5/13 12:16 PM, Lockhart, Robert wrote: SHA-1 was deprecated by NIST at the end of 2010 for digital signature generation and is not allowed after December 31, 2013 (specifically in government applications and recommended guidance for the rest of us). It can be used for validation purposes for legacy signatures beyond end of year though but I don't see adding it to the specification if it doesn't already exist in the real world. See Pages 13 & 14 of SP800-131A for more details. http://csrc.nist.gov/publications/nistpubs/800-131A/sp800-131A.pdf Bob L.

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]