License
Rajesh Balla <[email protected]>
| Newsgroups | gmane.comp.encryption.cryptopp |
|---|---|
| Message-ID | <[email protected]> |
Hi The legal team in my company needs me to fill this questionairre for using Crypto++ in our commerical application (for AES GCM encryption). If you've done this before or are familiar with , could you please advise on how you would answer these questions? Thanks Rajesh *ECCN Questionnaire * *I. **TECHNICAL INFORMATION* 3. Does this product only use encryption key lengths that are: - 56 bits or less (symmetrical); or - 512 bits or less (asymmetrical); or - 112 bits or less (elliptic curve): Regardless of whether the answer is Yes or No, provide encryption algorithms and corresponding key lengths: ______ YES* - See Note to question 3, below. NO * - *Continue to the next question. * Note to question 3: If you answered *YES*, and you have provided the requested details above of the encryption used, and you are certain that the product contains no other encryption or cryptographic functionalities that exceed any of the above parameters, then you may *STOP HERE** and submit the form for technical review.* 4. Is the encryption in this product used *solely* for authentication purposes? (Authentication includes all aspects of access control where there is no encryption of files or text except as directly related to the protection of passwords, PINs or similar data to prevent unauthorized access.) This response should include (1) all encryption functionalities contained in/performed by the product *and* (2) those encryption functionalities of other products called on/specifically leveraged by the product YES - Provide type, strength and specific purpose of encryption algorithms used, then *STOP HERE,** and submit this form for review.* NO * - *Continue to the next question. 5. Is the software generally available to the public by being sold, without restriction, from stock at retail selling points (i.e., “off the shelf”) by means of any of the following: (1) Over-the-counter transactions (2) Mail order transactions (3) Electronic transactions; or (4) Telephone transactions? *Note:* Only check “Yes” if this is the type of product that anyone could walk into a store or go online to buy (or purchase through a similar mail-order or telephone transaction). YES - Describe *here* to whom and how the software is marketed/sold, and continue to the next question: NO * - *Continue to the next question. 6. Would a customer require considerable knowledge or special software to change the cryptographic functionality of the product (e.g., encryption algorithms, key management or key space)? YES - Describe *here* what *prevents* the customer from changing the encryption, and continue to the next question: NO * - *Describe *here* how the customer *could change* the encryption, and continue to the next question: 7. Is the software designed for installation by the customer without further substantial support by the supplier? YES - Continue to the next question. NO * - *Continue to the next question. 8. Does the product contain an Open Cryptographic Interface (“OCI”)? (see section IV for a definition of OCI) NO * - *This product *does not* contain an OCI. YES - This product contains the following OCI (describe in full): 9. Does the product fall into any of the following categories? Check all that apply, or check “no” if the software does not fall into any of the categories NO (A) Network infrastructure commodities and software, and parts and components thereof (including commodities and software necessary to activate or enable cryptographic functionality in network infrastructure products) providing secure Wide Area Network (WAN), Metropolitan Area Network (MAN), Virtual Private Network (VPN), digital packet telephony/media over internet protocol, satellite, cellular or trunked communications meeting *any of the following* with key lengths exceeding 80-bits for symmetric algorithms: (1) Aggregate encrypted WAN, MAN, VPN or backhaul throughput (includes communications through wireless network elements such as gateways, mobile switches, controllers, etc) greater than 90 Mbps.; or (2) Wire (line), cable or fiber-optic WAN, MAN or VPN single-channel input data rate exceeding 154 Mbps; or (3) Transmission over satellite at data rates exceeding 10 Mbps; or (4) Media (voice/data/video) encryption or centralized key management supporting more than 250 concurrent encrypted data channels, or encrypted signaling to more than 1,000 endpoints, for digital packet telephony/media (voice/video/data) over internet protocol communications; or (5) Air-interface coverage (e.g., through base stations, access points to mesh networks, bridges, etc.) exceeding 1,000 meters, where any of the following applies: (i) Maximum data rates exceeding 10 MBPS (at operating ranges beyond 1,000 meters); or (ii) Maximum number of concurrent full-duplex voice channels exceeding 30; or (iii) Substantial support is required for installation or use. (B) Encryption source code (C) Encryption software, commodities and components that have any of the following: (1) Been modified or customized for government end-user(s) (e.g. a non-U.S. government department, agency, or other entity that performs government functions); or (2) Cryptographic functionality that has been modified or customized to customer specification; or (3) Cryptographic functionality or encryption component (except encryption software that would be considered publicly available, as that term is defined in section (B) above) that is user-accessible and can be easily changed by the user. *Note:* an encryption component is any encryption commodity or software (except source code) including encryption chips, integrated circuits, application specific encryption toolkits, or executable or linkable modules that alone are incapable of performing complete cryptographic functions, and is designed or intended for use in or the production of another encryption item. (D) Encryption commodities and software that provide functions necessary for quantum cryptography; or (E) Encryption commodities and software that have been modified or customized for specialized digital computers or electronic assemblies designed for fault tolerance; or having an Adjusted Peak Performance (APP) exceeding 0.75 weighted TeraFLOPS; or specially designed or modified to be capable of enhancing performance by aggregation of processors so that the APP exceeds 0.75 weighted TeraFLOPS; or that perform analog-to-digital conversions exceeding the parameters of 3A001.a.5; or equipment specially designed for aggregating the performance of digital computers by providing external interconnections which allow communications at unidirectonal data rates exceeding 2.0 Gbyte/s per link; or (F) Encryption commodities and software that provide penetration capabilities that are capable of attacking, denying, disrupting or otherwise impairing the use of cyber infrastructure or networks; or (G) Public safety/first responder radio. (H) Cryptanalytic commodities and software (those items designed or modified to perform cryptanalytic functions, such as the analysis of a cryptographic system or its inputs and outputs to derive confidential variables or sensitive data including clear text. This would include password-guessing and crypto-breaking software. (Functions specially designed and limited to protect against malicious computer damage or unauthorized system intrusion are not cryptanalytic functions)). 10. Does the product fall into any of the following categories? Check all that apply, or check “no” if the software does not fall into any of the categories NO (A) Encryption chips, chipsets, electronic assemblies and field programmable logic devices; or (B) Cryptographic libraries, modules, development kits and toolkits, including for operating systems and cryptographic service providers (CSPs); or (C) Application-specific hardware or software development kits implementing cryptography; or (D) Encryption commodities, software and components that provide or perform “non-standard” cryptography (i.e., implementation of cryptography involving the incorporation or use of *proprietary or unpublished cryptographic functionality*, including encryption algorithms or protocols that have not been adopted or approved by a duly recognized international standards body (e.g., IEEE, IETF, ISO, ITU, ETSI, 3GPP, TIA, and GSMA) and have not otherwise been published) [*Note*: All encryption mechanisms implement proprietary algorithms unless: *(1) There is an IDENTICAL copy of the code for the encryption mechanism available on the Internet (for a fee or free)*; or *(2) The algorithm is sourced from a third party mechanism such as Adobe, Microsoft, a third party library, etc.*]; or (E) Encryption commodities and software that provide or perform vulnerability analysis, network forensics, or computer forensics functions; or (F) Commodities, software and components that activate or enable cryptographic functionality in encryption products that would otherwise remain disabled. -- You received this message because you are subscribed to "Crypto++ Users". More information about Crypto++ and this group is available at http://www.cryptopp.com and http://groups.google.com/forum/#!forum/cryptopp-users. --- You received this message because you are subscribed to the Google Groups "Crypto++ Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/cryptopp-users/d16638e1-ed8e-49d6-867d-87f0c4efce2en%40googlegroups.com.