I prefer to have the standard mandate unencumbered methods when they are reasonable alternatives readily available. It appears to me that more implementations could be compliant by mandating the 128 bit strength. A note could be added to capture concerns for more stringent requirements in some environments. It is unfortunate that the vote is going to drag into the debate not only the strengths, but also the algorithms.
In 800-57, it specs (for unclassified applications):
min. 80 bits until year 2010
min. 112 bits until year 2011 to 2030
min. 128 bits thereafter
Also, it appears that in 06-449r8 there could be an error in the 128 bit column. It seems to match the 800-57 documents' 112 bit column more closely. The attached doc shows the equivalent strengths for various algorithms from SP 800-57. I believe 3072 is required for DH/RSA 128 bit equivalency, correct?
Regards,
Larry Hofer
Office of Technology, Emulex
| "Gideon Avida"
<gideon@decru.com> Sent by: owner-t10@t10.org 09/13/2007 01:03 PM |
|
| "Gideon Avida"
<gideon@decru.com>
09/13/2007 12:35 PM |
|