NSA’s Elliptic Curve Licensing Agreement Mr. John Stasak Cryptography Office Information Assurance...

10
NSA’s Elliptic Curve Licensing Agreement Mr. John Stasak Cryptography Office Information Assurance Research National Security Agency

Transcript of NSA’s Elliptic Curve Licensing Agreement Mr. John Stasak Cryptography Office Information Assurance...

Page 1: NSA’s Elliptic Curve Licensing Agreement Mr. John Stasak Cryptography Office Information Assurance Research National Security Agency Mr. John Stasak Cryptography.

NSA’s Elliptic Curve Licensing AgreementNSA’s Elliptic Curve

Licensing Agreement

Mr. John StasakCryptography Office

Information Assurance Research

National Security Agency

Mr. John StasakCryptography Office

Information Assurance Research

National Security Agency

Page 2: NSA’s Elliptic Curve Licensing Agreement Mr. John Stasak Cryptography Office Information Assurance Research National Security Agency Mr. John Stasak Cryptography.

Why Elliptic Curve Cryptography Is Important to

NSA

Why Elliptic Curve Cryptography Is Important to

NSA

• The next generation cryptography to protect USG information will use elliptic curve cryptography

• Increased security obtained with reduced bandwidth over conventional methods

• The next generation cryptography to protect USG information will use elliptic curve cryptography

• Increased security obtained with reduced bandwidth over conventional methods

Page 3: NSA’s Elliptic Curve Licensing Agreement Mr. John Stasak Cryptography Office Information Assurance Research National Security Agency Mr. John Stasak Cryptography.

Overview of License AgreementOverview of License Agreement

• Field of Use• NSA Approved Product• Licensed Patents and Patent Applications• Sublicensing Rights

• Field of Use• NSA Approved Product• Licensed Patents and Patent Applications• Sublicensing Rights

Page 4: NSA’s Elliptic Curve Licensing Agreement Mr. John Stasak Cryptography Office Information Assurance Research National Security Agency Mr. John Stasak Cryptography.

Field Of UseField Of Use

• The Licensed Patents and Patent Applications with elliptic curves over GF(p), where p is a prime number greater than 2255 and

• Either NSA Approved Product or a product for national security compliant with FIPS 140-2 or its successors

• The Licensed Patents and Patent Applications with elliptic curves over GF(p), where p is a prime number greater than 2255 and

• Either NSA Approved Product or a product for national security compliant with FIPS 140-2 or its successors

Page 5: NSA’s Elliptic Curve Licensing Agreement Mr. John Stasak Cryptography Office Information Assurance Research National Security Agency Mr. John Stasak Cryptography.

NSA Approved ProductNSA Approved Product

• A product that is approved by NSA for use by either:

– Federal, State or Local government agencies protecting classified or mission critical national security information, or

• A product that is approved by NSA for use by either:

– Federal, State or Local government agencies protecting classified or mission critical national security information, or

Page 6: NSA’s Elliptic Curve Licensing Agreement Mr. John Stasak Cryptography Office Information Assurance Research National Security Agency Mr. John Stasak Cryptography.

NSA Approved ProductNSA Approved Product

– Foreign government agencies for protecting classified or mission critical national security information where interoperability with US entities is a possibility or for protecting classified or mission critical national security information that originated in the U.S. Federal, State or Local Government

– Foreign government agencies for protecting classified or mission critical national security information where interoperability with US entities is a possibility or for protecting classified or mission critical national security information that originated in the U.S. Federal, State or Local Government

Page 7: NSA’s Elliptic Curve Licensing Agreement Mr. John Stasak Cryptography Office Information Assurance Research National Security Agency Mr. John Stasak Cryptography.

Licensed Patents and Patent Applications

Licensed Patents and Patent Applications

• Key Agreement and Transport Protocol – with Implicit Signatures– With Implicit Signature and Reduced Bandwidth

• Digital Signatures on a Smartcard• Strengthened Public Key Protocol• Elliptic Curve Encryption Systems• Authenticated Key Agreement

• Key Agreement and Transport Protocol – with Implicit Signatures– With Implicit Signature and Reduced Bandwidth

• Digital Signatures on a Smartcard• Strengthened Public Key Protocol• Elliptic Curve Encryption Systems• Authenticated Key Agreement

Page 8: NSA’s Elliptic Curve Licensing Agreement Mr. John Stasak Cryptography Office Information Assurance Research National Security Agency Mr. John Stasak Cryptography.

Sublicensing RightsSublicensing Rights

• NSA has a perpetual nonexclusive, nontransferable, worldwide, royalty free, fee-bearing license under the Licensed Patents and Patent Applications within the Field of Use to make, have made, use, sell, offer for sale, and import Licensed Products for use by End Users and to practice the Licensed Processes in the Field of Use, as well as to sublicense to others

• NSA has a perpetual nonexclusive, nontransferable, worldwide, royalty free, fee-bearing license under the Licensed Patents and Patent Applications within the Field of Use to make, have made, use, sell, offer for sale, and import Licensed Products for use by End Users and to practice the Licensed Processes in the Field of Use, as well as to sublicense to others

Page 9: NSA’s Elliptic Curve Licensing Agreement Mr. John Stasak Cryptography Office Information Assurance Research National Security Agency Mr. John Stasak Cryptography.

What is Really CoveredWhat is Really Covered

• The use of elliptic curves defined over GF(p) where p is a prime number greater than 2255 when the product satisfies the Field of Use conditions

• Both compressed and uncompressed point implementations

• Use of elliptic curve MQV and ECDSA under the above conditions

• The use of elliptic curves defined over GF(p) where p is a prime number greater than 2255 when the product satisfies the Field of Use conditions

• Both compressed and uncompressed point implementations

• Use of elliptic curve MQV and ECDSA under the above conditions

Page 10: NSA’s Elliptic Curve Licensing Agreement Mr. John Stasak Cryptography Office Information Assurance Research National Security Agency Mr. John Stasak Cryptography.

Who to Contact to Get a NSA License

Who to Contact to Get a NSA License

• NSA’s Information Assurance Business Affairs Office– National Security Agency

Attn: IAD Business Affairs Office

9800 Savage Road, Suite 6740

Fort Meade, MD 20755-6740– 410-854-6091– [email protected]

• NSA’s Information Assurance Business Affairs Office– National Security Agency

Attn: IAD Business Affairs Office

9800 Savage Road, Suite 6740

Fort Meade, MD 20755-6740– 410-854-6091– [email protected]