Department OF Commerce

National Institute of Standards and Technology

RIN 0693-AB09

Proposed Reaffirmation of Federal Information Processing Standard (FIPS)
46-1, Data Encryption Standard (DES)

Friday, September 11, 1992

AGENCY: National Institute of Standards and Technology (NIST), Commerce.

ACTION: Notice; request for comments.

SUMMARY: Federal Information Processing Standard 46, Data Encryption
Standard, issued in 1977, provides an algorithm to be implemented in
electronic hardware devices and used for the cryptographic protection of
computer data.  The standard provided that it be reviewed within five (5)
years to assess its adequacy. The first review was completed in 1983, and
the standard was reaffirmed for Federal government use (48 FR 41062 dated
September 13, 1983). The second review was completed in 1987, and the
standard was reaffirmed for Federal government use (52 FR 7006).

The purpose of this notice is to announce the review to assess the
continued adequacy of the standard to protect computer data. Comments from
industry and the public are invited on the following alternatives for FIPS
46-1.  The costs (impacts) and benefits of these alternatives should be
included in the comments:

-Reaffirm the standard for another five (5) years.  The National
Institute of Standards and Technology would continue to validate equipment
that implements the standard.  FIPS 46-1 would continue to be the only
approved method for protecting unclassified computer data.

-Withdraw the standard.  The National Institute of Standards and
Technology would no longer continue to support the standard. Organizations
could continue to utilize existing equipment that implements the standard.
Other standards could be issued by NIST as a replacement for the DES.

-Revise the applicability and/or implementation statements of the
standard. Such revisions could include changing the standard to allow the
use of implementations of the DES in software as well as hardware; to
allow the iterative use of the DES in specific applications; to allow the
use of alternative algorithms that are approved and registered by NIST.

Interested parties may obtain a copy of FIPS 46-1 from the National
Technical Information Service (NTIS), 5285 Port Royal Road, Springfield,
VA 22161, telephone (703) 487-4650.

DATES: Comments on this review of FIPS 46-1 must be received on or before
December 10, 1992.

ADDRESSES: Written comments concerning this standard should be sent to:
Director, Computer Systems Laboratory, ATTN: Review of FIPS 46-1,
Technology Building, room B-154, National Institute of Standards and
Technology, Gaithersburg, MD 20899.

Written comments received in response to this notice will be made part of
the public record and will be made available for inspection and copying in
the Central Reference and Records Inspection Facility, room 6020, Herbert
C. Hoover Building, 14th Street between Pennsylvania and Constitution
Avenues NW., Washington, DC 20230.

FOR FURTHER INFORMATION CONTACT:Mr. Miles Smid (301-975-2938) or Donna F.
Dodson (301-975-2921), National Institute of Standards and Technology,
Gaithersburg, MD 20899.

Dated: September 4, 1992.

John W. Lyons,

Director.
