National Encryption Standards

Traffic Light Protocol (TLP):

  • This marking protocol is widely used around the world. It has four colors (traffic lights):

    • Red – Personal, Confidential and for Intended Recipient Only The recipient has no rights to share information classified in red with any person outside the defined range of recipients either inside or outside the organization.

    • Amber – Restricted Sharing The recipient may share information classified in amber only with intended recipients inside the organization and with recipients who are required to take action related to the shared information.

    • Green – Sharing within the Same Community The recipient may share information classified in green with other recipients inside the organization or outside it within the same sector or related to the organization. However, it is not allowed to exchange or publish this information on public channels.

    • White - No Restrictions

Executive Summary

1 Introduction

1.2 Levels of Cryptographic Standards

  • The NCS defines two strength levels for cryptographic standards: the MODERATE level and the ADVANCED level. Having two strength levels provides more flexibility to choose the appropriate level of protection for different classes of data, systems and networks. Each national entity is required to choose and implement the appropriate cryptographic standard level based on the nature and sensitivity of the data, systems and networks to be protected. Furthermore, other cybersecurity regulations, issued by the NCA, may mandate the use of a particular cryptographic standard level to protect data, systems and networks. The MODERATE and ADVANCED strength levels are designed to target 128-bit and 256-bit security levels, respectively. Specific requirements for each strength level are specified throughout this document. Any requirement not specifically associated with one of these two strength levels applies equally to both.

1.3 Structure of the Document

  • The rest of this document is organized as follows. Section 2 lists the accepted symmetric and asymmetric primitives with their key, block and initialization vector sizes. Section 3 provides the accepted symmetric and asymmetric schemes: block cipher modes of operation, MAC, AEAD, key wrap functions, key derivation functions, key agreement, key transport, hybrid encryption and public key signatures. Section 4 provides requirements for the most prevalent application protocols such as DNS Security (DNSSEC), IP Security (IPsec), Bluetooth, SSH, TLS, UMTS/LTE/5G, WPA and Kerberos. Section 5 provides a list of the accepted algorithms for certificates and the validity of the certificates. Section 6 provides the requirements for the different steps of the key lifecycle to ensure that keys are managed properly from the moment they are created until their destruction, and their usage is standardized across processes. Finally, Section 7 provides appendices that present some information about Pseudo Random Number Generation (PRNG), Post-Quantum Cryptography, Side-Channel Attacks, Definitions and Acronyms.

2 Cryptographic Primitives

2.1.1 Stream Cipher Algorithms

  • Accepted stream cipher algorithms:

    • • SNOW 2.0 (ISO/IEC 18033-4)

    • . 128-bit key length for MODERATE.

    • . 256-bit key length for ADVANCED.

    • • SOSEMANUK1 (from eSTREAM project)

    • . 128-bit and 256-bit key lengths for MODERATE.

    • . Not accepted for ADVANCED.

  • Common notes:

    • • Initialization Vector (IV) must be at least 128 bits.

    • • Stream ciphers must be used with a different IV for each key.

    • • A key must be used only once.

    • • Valid decryption must never be relied on for authenticity.

2.1.2 Block Ciphers Algorithms

  • Accepted block cipher algorithms:

    • • Advanced Encryption Standards (AES) as in FIPS-197

    • . 128-bit and 192-bit key lengths for MODERATE.

    • . 256-bit key length for ADVANCED.

  • • Camellia (ISO/IEC 18033-3)

    • . 128-bit and 192-bit key lengths for MODERATE.

    • . 256-bit key length for ADVANCED.

  • • Serpent2

    • . 128-bit and 192-bit key lengths for MODERATE.

    • . 256-bit key length for ADVANCED.

Next section title

Next section content