Suite B Cryptography for Classified Networks

In February of 2005, the National Security Agency (NSA) released Suite B Cryptography, a set of four standardized cryptographic algorithms. Since its release, a number of cable contractors have offered Suite B cryptographic solutions to businesses and organizations to protect a wide range of data and information, from unclassified to most classified.

While most cable contractors provided proper Suite B solutions, many falsely advertised that their products met NSA Suite B certifications. The problem with this is that official certification processes didn’t yet exist, meaning the vendor’s products may or may not have provided proper security of information passed through public networks.

To ensure that you are receiving the best possible security for your information when working with a cable contractor, check to make sure that their Suite B solutions consist of the following:

  • Block Encryption. This encryption should be established with the Advanced Encryption Standard (AES) in Galois/Counter Mode (GCM). Key sizes should be either 128 or 256 bits.
  • Digital Signatures. Suite B products should contain the Elliptic-Curve Digital Signature Algorithm (ECDSA).
  • Key Agreement. This component should be established using the Elliptic-Curve Diffie-Hellman algorithm (ECDH).
  • Message Digests. Suite B products should have message digests developed through the Secure Hash Algorithm (SHA). The proper algorithms for this cryptography are SHA-256 for information up to the Secret level and SHA-384 for information at the Top Secret level.

In addition to the above, the NSA has created a tool called the Conformance Evaluator (ICE) that helps to determine compliance of internet protocol security against Suite B regulations. Make sure to check that the cable contractor you work with has designed solutions that comply with this standard.

