Fwd: [pqc-forum] Call for comments: ipd SP 800-133r3 Recommendation for Cryptographic Key Generation

Ira McDonald via ipp <[email protected]> Thu, 7 May 2026 14:48:15 -0400
Newsgroups gmane.ietf.ipp
Message-ID <CAN40gStnmj27qX-9_EirAvgHsCdoP10BGO4dG1LGHbBUpxOvdg@mail.gmail.com>
--===============1369323333829393155==
Content-Type: multipart/alternative; boundary="0000000000001947e606513eba5b"

--0000000000001947e606513eba5b
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi,

This NIST SP800-133 spec is finally being revised to align with updated
NIST SP800-90A/B/C
(Entropy and RNGs) and NIST PQC standards (FIPS 203, 204, 205 and future
206 and 207).

Crypto Key Generation underlies a whole lot of NIST specs.  They have said
that SP800-133
will go to full standard in the next release in later 2026.

Cheers,
- Ira

---------- Forwarded message ---------
From: 'Hamilton Silberg' via pqc-forum <[email protected]>
Date: Fri, Apr 17, 2026 at 9:54=E2=80=AFAM
Subject: [pqc-forum] Call for comments: ipd SP 800-133r3 Recommendation for
Cryptographic Key Generation
To: pqc-forum <[email protected]>


Hello all,

The initial public draft (ipd) of NIST SP 800-133r3 (Revision 3),
Recommendation for Cryptographic Key Generation, is available for public
comment.

Proposed changes in this revision include the following:
=E2=80=A2 Asymmetric key-pair generation has been expanded to include metho=
ds for
deriving randomness during key-pair generation.
=E2=80=A2 Key-pair generation now has options for derivation similar to sym=
metric
keys and new methods for =E2=80=9Cseed expansion,=E2=80=9D which allows for=
 the limited use
of SHAKE and deterministic random bit generators (DRBGs).
=E2=80=A2 Key-encapsulation mechanisms (KEMs) are discussed as a key-establ=
ishment
option for symmetric key generation, and post-quantum cryptography (PQC)
references have been added throughout (e.g., the new PQC signatures).
=E2=80=A2 Text has been reworded to address random number generation in ali=
gnment
with SP 800-90C.


Comments are especially requested regarding:
=E2=80=A2 Hardware security module (HSM) design =E2=80=94 How do these requ=
irements align
with common practice and existing systems using a root seed/secret value?
=E2=80=A2 PQC implementations and protocols =E2=80=94 How do these requirem=
ents fit with
storing keys as seeds (e.g., for ML-KEM) and performing hybrid (i.e.,
combined classical and post-quantum) implementations?

The public comment period will be open through June 16, 2026.
See: https://csrc.nist.gov/pubs/sp/800/133/r3/ipd

Best,
-Hamilton Silberg
NIST PQC

--=20
You received this message because you are subscribed to the Google Groups
"pqc-forum" group.
To unsubscribe from this group and stop receiving emails from it, send an
email to [email protected].
To view this discussion visit
https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/eb4929b9-119e-4=
f8f-a221-04976ea72d51n%40list.nist.gov
<https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/eb4929b9-119e-=
4f8f-a221-04976ea72d51n%40list.nist.gov?utm_medium=3Demail&utm_source=3Dfoo=
ter>
.

--0000000000001947e606513eba5b
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Hi,</div><div><br></div><div>This NIST SP800-133 spec=
 is finally being revised to align with updated NIST SP800-90A/B/C</div><di=
v>(Entropy and RNGs) and NIST PQC standards (FIPS 203, 204, 205 and future =
206 and 207).</div><div><br></div><div>Crypto Key Generation underlies a wh=
ole lot of NIST specs.=C2=A0 They have said that SP800-133</div><div>will g=
o to full standard in the next release in later 2026.</div><div><br></div><=
div>Cheers,</div><div>- Ira</div><br><div class=3D"gmail_quote gmail_quote_=
container"><div dir=3D"ltr" class=3D"gmail_attr">---------- Forwarded messa=
ge ---------<br>From: <b class=3D"gmail_sendername" dir=3D"auto">&#39;Hamil=
ton Silberg&#39; via pqc-forum</b> <span dir=3D"auto">&lt;<a href=3D"mailto=
:[email protected]">[email protected]</a>&gt;</span><br>Date: F=
ri, Apr 17, 2026 at 9:54=E2=80=AFAM<br>Subject: [pqc-forum] Call for commen=
ts: ipd SP 800-133r3 Recommendation for Cryptographic Key Generation<br>To:=
 pqc-forum &lt;<a href=3D"mailto:[email protected]">[email protected]=
st.gov</a>&gt;<br></div><br><br>Hello all,<br><br>The initial public draft =
(ipd) of NIST SP 800-133r3 (Revision 3), Recommendation for Cryptographic K=
ey Generation, is available for public comment. <br><br>Proposed changes in=
 this revision include the following:<br>=E2=80=A2<span style=3D"white-spac=
e:pre-wrap">	</span>Asymmetric key-pair generation has been expanded to inc=
lude methods for deriving randomness during key-pair generation.<br>=E2=80=
=A2<span style=3D"white-space:pre-wrap">	</span>Key-pair generation now has=
 options for derivation similar to symmetric keys and new methods for =E2=
=80=9Cseed expansion,=E2=80=9D which allows for the limited use of SHAKE an=
d deterministic random bit generators (DRBGs).<br>=E2=80=A2<span style=3D"w=
hite-space:pre-wrap">	</span>Key-encapsulation mechanisms (KEMs) are discus=
sed as a key-establishment option for symmetric key generation, and post-qu=
antum cryptography (PQC) references have been added throughout (e.g., the n=
ew PQC signatures).<br>=E2=80=A2<span style=3D"white-space:pre-wrap">	</spa=
n>Text has been reworded to address random number generation in alignment w=
ith SP 800-90C.<br><br><br>Comments are especially requested regarding:<br>=
=E2=80=A2<span style=3D"white-space:pre-wrap">	</span>Hardware security mod=
ule (HSM) design =E2=80=94 How do these requirements align with common prac=
tice and existing systems using a root seed/secret value?<br>=E2=80=A2<span=
 style=3D"white-space:pre-wrap">	</span>PQC implementations and protocols =
=E2=80=94 How do these requirements fit with storing keys as seeds (e.g., f=
or ML-KEM) and performing hybrid (i.e., combined classical and post-quantum=
) implementations?<br><br>The public comment period will be open through Ju=
ne 16, 2026.<br>See: <a href=3D"https://csrc.nist.gov/pubs/sp/800/133/r3/ip=
d" target=3D"_blank">https://csrc.nist.gov/pubs/sp/800/133/r3/ipd</a><br><b=
r>Best,<br>-Hamilton Silberg<br>NIST PQC

<p></p>

-- <br>
You received this message because you are subscribed to the Google Groups &=
quot;pqc-forum&quot; group.<br>
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:[email protected]" target=3D"_b=
lank">[email protected]</a>.<br>
To view this discussion visit <a href=3D"https://groups.google.com/a/list.n=
ist.gov/d/msgid/pqc-forum/eb4929b9-119e-4f8f-a221-04976ea72d51n%40list.nist=
.gov?utm_medium=3Demail&amp;utm_source=3Dfooter" target=3D"_blank">https://=
groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/eb4929b9-119e-4f8f-a221=
-04976ea72d51n%40list.nist.gov</a>.<br>
</div></div>

--0000000000001947e606513eba5b--

--===============1369323333829393155==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
ipp mailing list
[email protected]
https://www.pwg.org/mailman/listinfo/ipp

--===============1369323333829393155==--