Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Deciphering the world of crypto

IETF opens its arms to lesser-known algorithms such as SEED and GOST.
By Ellen Messmer , Network World , 10/24/2005
  • Share/Email
  • Comment
  • Print

 It's the computational magic for scrambling data to keep it secret, and in the U.S., the best-known cryptographic algorithms go by names such as Triple-DES and AES.

But in other countries, such as South Korea, Russia and Japan, it is SEED, GOST and Camellia that say security, say nothing of specialized cryptos such as CAVE and A5/1.

It's a wide world of encryption, and the IETF, which shepherds Internet protocols, is embracing it.

The IETF standards for Web, VPN and e-mail security have been driven with crypto algorithms approved by the U.S. government, primarily via the National Institute of Standards and Technology.

Triple-DES is defined as a must for any product implementation based on IETF standards. The newer 128-bit Advanced Encryption Standard (AES) - a cipher invented by Belgian cryptographers that was selected as the U.S. standard in late 2001 after a five-year review - will eventually gain must-have status.

The IETF isn't in the job of vetting crypto algorithms, as that's regarded as a job for government agencies throughout the world, typically with a lot of input from outside experts. But the IETF is careful to include only sound crypto into its protocols.

Like practically everything in the IETF standards process, getting new crypto into IETF protocols such as Secure Multi-purpose Internet Mail Extensions (S/MIME), IPSec and Transport Layer Security (TLS) can take years. The Russians and the South Koreans have been among the most persevering in seeking to get their national ciphers through the process.

In a sign of success, several IETF RFCs recently were issued for using South Korea's 128-bit symmetric key SEED and the Russian 256-bit GOST, which is extensible to 768 bits. (The longer the key size, the presumably harder it is to break encrypted data, though other factors define an algorithm's intrinsic strength.)

"In this conscious effort to register a cipher suite, they're being good Internet citizens," says Russ Housley, the IETF security area director who heads his own firm, Vigil Security.

SEED, developed by the Korean Information Security Agency (KISA), is defined for use in TLS and S/MIME, with IPSec support on the way. Four of KISA's security experts, Hyangjin Lee, Jaeho Yoon, Seoklae Lee and Jaeil Lee, wrote the technical drafts, detailing use of SEED and testifying that it is "robust against known attacks." It is said to be widely used by financial services companies, including the Bank of Korea, for VPN and digital rights management. SEED is supported in products from an assortment of global companies, including Chrysalis-ITS, nCipher, Rainbow Technologies and Schlumberger.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed

Whitepapers

Windows Vista: Necessity and Opportunity

The Vista era of Windows is here. Yet most organizations will retain Windows XP alongside new Vista...

Vulnerability Management For Dummies

Download this concise book "Vulnerability Management for Dummies," to learn about the simple steps...

Security Considerations When Deploying Remote Access Solutions

Effective network security is most successful when you use a layered approach, with multiple...

Webcasts

Migrating to Windows Vista: Necessity and Opportunity

The Vista era of Windows is here. Yet most organizations will retain Windows XP alongside new Vista...

Turning information into a Competitive Advantage

Companies today are realizing that competitive advantage is harder to sustain when based solely on...

PoE Plus: Impact on the PoE Market

The standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Special Reports

Unified Threat Management from CheckPoint

Discover why Unified Threat Management Firewalls are ready for the enterprise today. High...

The Evolution of Network Security

We have so many holes punched in our firewalls today that many industry insiders question the value...

The self-managed network

We aren't there yet, but advances in network and systems management tools are making it possible to...

Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Network World,to go. Wherever you are. Breaking news delivered to your mobile device. Select the hottest topics in networking and start receiving Network World on your mobile device today.