ARTICLE
4 July 2023

NIST To Withdraw Approval For Triple-DES Algorithm

FL
Foley & Lardner

Contributor

Foley & Lardner LLP looks beyond the law to focus on the constantly evolving demands facing our clients and their industries. With over 1,100 lawyers in 24 offices across the United States, Mexico, Europe and Asia, Foley approaches client service by first understanding our clients’ priorities, objectives and challenges. We work hard to understand our clients’ issues and forge long-term relationships with them to help achieve successful outcomes and solve their legal issues through practical business advice and cutting-edge legal insight. Our clients view us as trusted business advisors because we understand that great legal service is only valuable if it is relevant, practical and beneficial to their businesses.
The National Institute of Science and Technology (NIST) is officially sunsetting the use of the old DES Data Encryption Algorithm (DEA). Although the single-key version of it was withdrawn almost...
United States Technology

The National Institute of Science and Technology (NIST) is officially sunsetting the use of the old DES Data Encryption Algorithm (DEA). Although the single-key version of it was withdrawn almost 20 years ago, the stronger three-key versions (2TDEA and 3TDEA) have been permitted to give organizations a chance to transition. That transition period is now officially over and the withdrawal of the special publication will be effective on January 1, 2024.

DES is an outdated encryption algorithm developed by IBM that was the standard (unclassified) encryption algorithm adopted by U.S. government agencies in the mid-late 1970's (FIPS Pub. 46) but has largely been replaced with the "Advanced Encryption Standard" generally known as AES. The move comes after multiple revisions of NIST's guidance in SP8--67, which successively added additional limitations on this old algorithms use. The withdrawal of the standards means that DEA will only be permitted for limited purposes, like decryption and continued functionality with data that already used DEA, but not used to protect any new data after December 31, 2023.

While few businesses, if any, should still be using DES in any form, businesses should verify that legacy systems (and systems used by their vendors) have transitioned off of it. This is especially important for businesses that may be in the supply chain for products and services used by the United States federal government, as these services will need to be updated prior to the effective date of the withdrawal.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More