License

Rajesh Balla <[email protected]>
Newsgroups gmane.comp.encryption.cryptopp
Message-ID <[email protected]>

Hi 

The legal team in my company needs me to fill this questionairre for using 
Crypto++ in our commerical application (for AES GCM encryption). If you've 
done this before or are familiar with , could you please advise on how you 
would answer these questions?


Thanks

Rajesh



*ECCN Questionnaire *

*I.              **TECHNICAL INFORMATION*

3.      

Does this product only use encryption key lengths that are:

- 56 bits or less (symmetrical); or

- 512 bits or less (asymmetrical); or

- 112 bits or less (elliptic curve):

Regardless of whether the answer is Yes or No, provide encryption 
algorithms and corresponding key lengths: ______

YES*  - See Note to question 3, below.

NO    * - *Continue to the next question.

* Note to question 3:  If you answered *YES*, and you have provided the 
requested details above of the encryption used, and you are certain that 
the product contains no other encryption or cryptographic functionalities 
that exceed any of the above parameters, then you may *STOP HERE** and 
submit the form for technical review.*

 

4.      

Is the encryption in this product used *solely* for authentication 
purposes?  (Authentication includes all aspects of access control where 
there is no encryption of files or text except as directly related to the 
protection of passwords, PINs or similar data to prevent unauthorized 
access.)  This response should include (1) all encryption functionalities 
contained in/performed by the product *and* (2) those encryption 
functionalities of other products called on/specifically leveraged by the 
product

YES  - Provide type, strength and specific purpose of encryption algorithms 
used, then *STOP HERE,** and submit this form for review.*

NO    * - *Continue to the next question.

5.      

Is the software generally available to the public by being sold, without 
restriction, from stock at retail selling points (i.e., “off the shelf”) by 
means of any of the following:

(1) Over-the-counter transactions

(2) Mail order transactions

(3) Electronic transactions; or

(4) Telephone transactions?

*Note:* Only check “Yes” if this is the type of product that anyone could 
walk into a store or go online to buy (or purchase through a similar 
mail-order or telephone transaction).

YES  - Describe *here* to whom and how the software is marketed/sold, and 
continue to the next question:       

 

NO    * - *Continue to the next question.

6.      

Would a customer require considerable knowledge or special software to 
change the cryptographic functionality of the product (e.g., encryption 
algorithms, key management or key space)?

YES  - Describe *here* what *prevents* the customer from changing the 
encryption, and continue to the next question:      

NO    * - *Describe *here* how the customer *could change* the encryption, 
and continue to the next question:       

 

7.      

Is the software designed for installation by the customer without further 
substantial support by the supplier?

YES  - Continue to the next question.

NO   * - *Continue to the next question.

8.      

Does the product contain an Open Cryptographic Interface (“OCI”)? 

(see section IV for a definition of OCI)

NO   * - *This product *does not* contain an OCI.

YES  - This product contains the following OCI (describe in full):       

 

9.      

Does the product fall into any of the following categories?

 

Check all that apply, or check “no” if the software does not fall into any 
of the categories

NO   

 (A) Network infrastructure commodities and software, and parts and 
components thereof (including commodities and software necessary to 
activate or enable cryptographic functionality in network infrastructure 
products) providing secure Wide Area Network (WAN), Metropolitan Area 
Network (MAN), Virtual Private Network (VPN), digital packet 
telephony/media over internet protocol, satellite, cellular or trunked 
communications meeting *any of the following* with key lengths exceeding 
80-bits for symmetric algorithms:

  (1) Aggregate encrypted WAN, MAN, VPN or backhaul throughput (includes 
communications through wireless network elements such as gateways, mobile 
switches, controllers, etc) greater than 90 Mbps.; or

  (2) Wire (line), cable or fiber-optic WAN, MAN or VPN single-channel 
input data rate exceeding 154 Mbps; or

  (3) Transmission over satellite at data rates exceeding 10 Mbps; or

  (4) Media (voice/data/video) encryption or centralized key management 
supporting more than 250 concurrent encrypted data channels, or encrypted 
signaling to more than 1,000 endpoints, for digital packet telephony/media 
(voice/video/data) over internet protocol communications; or

  (5) Air-interface coverage (e.g., through base stations, access points to 
mesh networks, bridges, etc.) exceeding 1,000 meters, where any of the 
following applies:

  (i) Maximum data rates exceeding 10 MBPS (at operating ranges beyond 
1,000 meters); or

  (ii) Maximum number of concurrent full-duplex voice channels exceeding 
30; or

  (iii) Substantial support is required for installation or use.

 (B) Encryption source code

 (C) Encryption software, commodities and components that have any of the 
following:

  (1) Been modified or customized for government end-user(s) (e.g. a 
non-U.S. government department, agency, or other entity that performs 
government functions); or

  (2) Cryptographic functionality that has been modified or customized to 
customer specification; or

  (3) Cryptographic functionality or encryption component (except 
encryption software that would be considered publicly available, as that 
term is defined in section (B) above) that is user-accessible and can be 
easily changed by the user.  *Note:* an encryption component is any 
encryption commodity or software (except source code) including encryption 
chips, integrated circuits, application specific encryption toolkits, or 
executable or linkable modules that alone are incapable of performing 
complete cryptographic functions, and is designed or intended for use in or 
the production of another encryption item.

 (D) Encryption commodities and software that provide functions necessary 
for quantum cryptography; or

 (E) Encryption commodities and software that have been modified or 
customized for specialized digital computers or electronic assemblies 
designed for fault tolerance; or having an Adjusted Peak Performance (APP) 
exceeding 0.75 weighted TeraFLOPS; or specially designed or modified to be 
capable of enhancing performance by aggregation of processors so that the 
APP exceeds 0.75 weighted TeraFLOPS; or that perform analog-to-digital 
conversions exceeding the parameters of 3A001.a.5; or equipment specially 
designed for aggregating the performance of digital computers by providing 
external interconnections which allow communications at unidirectonal data 
rates exceeding 2.0 Gbyte/s per link; or

 (F) Encryption commodities and software that provide penetration 
capabilities that are capable of attacking, denying, disrupting or 
otherwise impairing the use of cyber infrastructure or networks; or

 (G) Public safety/first responder radio.

 (H) Cryptanalytic commodities and software (those items designed or 
modified to perform cryptanalytic functions, such as the analysis of a 
cryptographic system or its inputs and outputs to derive confidential 
variables or sensitive data including clear text.  This would include 
password-guessing and crypto-breaking software.  (Functions specially 
designed and limited to protect against malicious computer damage or 
unauthorized system intrusion are not cryptanalytic functions)).

10.   

Does the product fall into any of the following categories?

 

Check all that apply, or check “no” if the software does not fall into any 
of the categories

NO   

 (A) Encryption chips, chipsets, electronic assemblies and field 
programmable logic devices; or

 (B) Cryptographic libraries, modules, development kits and toolkits, 
including for operating systems and cryptographic service providers (CSPs); 
or

 (C) Application-specific hardware or software development kits 
implementing cryptography; or

 (D) Encryption commodities, software and components that provide or 
perform “non-standard” cryptography (i.e., implementation of cryptography 
involving the incorporation or use of *proprietary or unpublished 
cryptographic functionality*, including encryption algorithms or protocols 
that have not been adopted or approved by a duly recognized international 
standards body (e.g., IEEE, IETF, ISO, ITU, ETSI, 3GPP, TIA, and GSMA) and 
have not otherwise been published) [*Note*:  All encryption mechanisms 
implement proprietary algorithms unless:

*(1) There is an IDENTICAL copy of the code for the encryption mechanism 
available on the Internet (for a fee or free)*; or

*(2) The algorithm is sourced from a third party mechanism such as Adobe, 
Microsoft, a third party library, etc.*]; or

 (E) Encryption commodities and software that provide or perform 
vulnerability analysis, network forensics, or computer forensics functions; 
or

 (F) Commodities, software and components that activate or enable 
cryptographic functionality in encryption products that would otherwise 
remain disabled.




 

-- 
You received this message because you are subscribed to "Crypto++ Users". More information about Crypto++ and this group is available at http://www.cryptopp.com and http://groups.google.com/forum/#!forum/cryptopp-users.
--- 
You received this message because you are subscribed to the Google Groups "Crypto++ Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion on the web visit https://groups.google.com/d/msgid/cryptopp-users/d16638e1-ed8e-49d6-867d-87f0c4efce2en%40googlegroups.com.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.