ConceptioArchiveNIST
NISTpublic full text

NIST SP 800-133r3 ipd: Recommendation for Cryptographic Key Generation

Quynh Dang (NIST); Dustin Moody (NIST); Andrew Regenscheid (NIST); Hamilton Silberg (NIST) · National Institute of Standards and Technology (NIST)
NIST · Standards · License: Public Domain
Open Source ↗
accesscontrolcomputersecurityidentityincidentresponsenistriskmanagement
cybersecurity, computer security, cryptography, access control, incident response, privacy, identity, risk management, NIST

You are viewing this page in an unauthorized frame window. This is a potential security issue, you are being redirected to https://csrc.nist.gov . An official website of the United States government Here’s how you know Here’s how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock Locked padlock icon ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites. Search Search CSRC MENU Search Search Projects Publications Expand or Collapse Drafts for Public Comment All Public Drafts Final Pubs FIPS (standards) Special Publications (SP s ) IR (interagency/internal reports) CSWP (cybersecurity white papers) ITL Bulletins Project Descriptions Journal Articles Conference Papers Books Topics Expand or Collapse Security & Privacy Applications Technologies Sectors Laws & Regulations Activities & Products News & Updates Events Glossary About CSRC Expand or Collapse Computer Security Division Cryptographic Technology Software Security Group Hardware Security Group Security Engineering and Risk Management Applied Cybersecurity Division Cybersecurity and Privacy Applications National Cybersecurity Center of Excellence (NCCoE) National Initiative for Cybersecurity Education (NICE) Contact Us Information Technology Laboratory Computer Security Resource Center Publications NIST SP 800-133 Rev. 3 (Initial Public Draft) Recommendation for Cryptographic Key Generation Share to Facebook Share to X Share to LinkedIn Share ia Email Documentation Topics Date Published: April 17, 2026 Comments Due: June 16, 2026 (public comment period is CLOSED) Email Questions to: [email protected] Planning Note ( 06/30/2026 ): The public comments received are now available. Author(s) Quynh Dang (NIST) , Dustin Moody (NIST) , Andrew Regenscheid (NIST) , Hamilton Silberg (NIST) Announcement This document describes the generation of keys to be managed and used by approved cryptographic algorithms. Proposed changes in this revision include the following: Asymmetric key-pair generation has been expanded to include methods for deriving randomness during key-pair generation. Key-pair generation now has options for derivation similar to symmetric keys and new methods for “seed expansion,” which allows for the limited use of SHAKE and deterministic random bit generators (DRBGs). Key-encapsulation mechanisms (KEMs) are discussed as a key-establishment option for symmetric key generation, and post-quantum cryptography (PQC) references have been added throughout (e.g., the new PQC signatures). Text has been reworded to address random number generation in alignment with SP 800-90C. Comments are especially requested regarding: Hardware security module (HSM) design — How do these requirements align with common practice and existing systems using a root seed/secret value? PQC implementations and protocol — How do these requirements fit with storing keys as seeds (e.g., for ML-KEM) and performing hybrid (i.e., combined classical and post-quantum) implementations? Abstract Cryptography is often used in an information technology security environment to protect data that is sensitive, has high value, or is vulnerable to unauthorized disclosure or undetected modification during transmission or while in storage. Cryptography relies upon two basic components: an algorithm (or cryptographic methodology) and a cryptographic key. This recommendation discusses the generation of the keys to be managed and used by the approved cryptographic algorithms. Cryptography is often used in an information technology security environment to protect data that is sensitive, has high value, or is vulnerable to unauthorized disclosure or undetected modification during transmission or while in storage. Cryptography relies upon two basic components: an algorithm... See full abstract Cryptography is often used in an information technology security environment to protect data that is sensitive, has high value, or is vulnerable to unauthorized disclosure or undetected modification during transmission or while in storage. Cryptography relies upon two basic components: an algorithm (or cryptographic methodology) and a cryptographic key. This recommendation discusses the generation of the keys to be managed and used by the approved cryptographic algorithms. Hide full abstract Keywords asymmetric key ; key agreement ; key derivation ; key generation ; key replacement ; key transport ; key wrapping ; private key ; public key ; symmetric key Control Families None selected Documentation Publication: https://doi.org/10.6028/NIST.SP.800-133r3.ipd Download URL Supplemental Material: Public comments received (pdf) Document History: 04/17/26: SP 800-133 Rev. 3 (Draft) Topics Security and Privacy key management HEADQUARTERS 100 Bureau Drive Gaithersburg, MD 20899 X (link is external) facebook (link is external) linkedin (link is external) instagram (link is external) youtube (link is external) rss govdelivery (link is external) Want updates about CSRC and our publications? Subscribe Contact Us | Our Other Offices Send inquiries to [email protected] Site Privacy Accessibility Privacy Program Copyrights Vulnerability Disclosure No Fear Act Policy FOIA Environmental Policy Scientific Integrity Information Quality Standards Commerce.gov Science.gov USA.gov Vote.gov

Related documents

Record · ID 27043 · SHA-256 651e34365cc99f7c
Conceptio Open Knowledge Archive — every document is proof-bundled with source, license, and retrieval metadata.