Approved Security Functions
Release Date:Jun 2, 2008
Last Updated:Nov 12, 2024
Approved Security Functions
The Approved Security Functions in JCMVP are specified below such as encryption functions, hash functions, and signature functions.
Public Key
Signature
- 1,DSA
- FIPS PUB 186-4, Digital Signature Standard (DSS), July 2013.
- Note: The length of the parameter p and q shall be 2048 bits or larger and 224 bits or larger, respectively.
- 2.ECDSA
- ANS X9.62-2005, Public Key Cryptography for the Financial Services Industry :
The Elliptic Curve Digital Signature Algorithm (ECDSA) - Note: The length of the order of the elliptic curve shall be 224 bits or larger and the length of the output of the hash function shall be 224 bits or larger.
- ANS X9.62-2005, Public Key Cryptography for the Financial Services Industry :
- 3.ECDSA
- FIPS PUB 186-4, Digital Signature Standard (DSS), July 2013
- Note: The length of the order of the elliptic curve shall be 224 bits or larger and the length of the output of the hash function shall be 224 bits or larger.
- 4.ECDSA
- SEC 1: Elliptic Curve Cryptography (May 21, 2009 Version 2.0)
- Note: The length of the order of the elliptic curve shall be 224 bits or larger and the length of the output of the hash function shall be 224 bits or larger.
- 5.RSASSA-PKCS1-v1_5
- PKCS#1 v2.2: RSA Cryptography Standard, October 27, 2012.
- Note: The length of the modulus shall be 2048 bits or larger and the length of the output of the hash function shall be 224 bits or larger.
- 6.RSASSA-PSS
- PKCS#1 v2.2: RSA Cryptography Standard, October 27, 2012.
- Note: The length of the modulus shall be 2048 bits or larger and the length of the output of the hash function shall be 224 bits or larger.
Confidentiality
- 7.RSA-OAEP
- PKCS#1 v2.2: RSA Cryptography Standard, October 27, 2012.
- Note: The length of the modulus shall be 2048 bits or larger and the length of the output of the hash function shall be 224 bits or larger.
Note: Reference Urls of PKCS#1 v2.2 have been changed to RFC8017.
Symmetric Key
128-bit block cipher
- 2.AES
- 3.Camellia
n-bit block cipher modes of operations
- 4.Electronic Codebook (ECB), Cipher Block Chaining (CBC), Cipher Feedback (CFB), Output Feedback (OFB), and Counter (CTR)
128-bit block cipher modes of operations
Stream cipher
Hash
- Secure Hash Standard (SHA-1, SHA-224, SHA-256, SHA-384 and SHA-512, SHA-512/224 and SHA-512/256)
- SHA-3 Hash Algorithms (SHA3-256, SHA3-384, SHA3-512)
- SHA-3 Extendable-Output Functions (SHAKE128, SHAKE256)
Message Authentication
- HMAC (HMAC-SHA-1, HMAC-SHA-224, HMAC-SHA-256, HMAC-SHA-384, HMAC-SHA-512, HMAC-SHA-512/224, and HMAC-SHA-512/256)
- The Keyed-Hash Message Authentication Code, FIPS PUB 198-1, July 2008.
- Note: Key length for HMAC generation shall be 112 bits or larger.
- CMAC
- Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication, NIST Special Publication 800-38B, May 2005 (Updated 10/6/2016).
- Note: CMAC using Triple-DES is not allowed.
- CCM
- GCM/GMAC
- GCM-AES-XPN
- IEEE Standards Association, Standard for Local and metropolitan area networks, Media Access Control (MAC) Security, Amendment 2: Extended Packet Numbering, 802.1AEbw-2013, February 12, 2013.
Random Number Generators
Deterministic random number generators
- Hash_DRBG, HMAC_DRBG and CTR_DRBG
- National Institute of Standards and Technology, Recommendation for Random Number Generation Using Deterministic Random Bit Generators, Special Publication 800-90A Revision 1, June 2015.
- Note: CTR_DRBG using Triple-DES is disallowed after December 31, 2019.
Non-deterministic Random number generators
There are no approved non-deterministic random number generators in JCMVP.
Key Establishment Schemes
Key agreement
- DH
- National Institute of Standards and Technology, Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography, Special Publication 800-56A Revision 3, April 2018.
- Note 1: The length of the parameter p and q shall be 2048 bits or larger and 224 bits or larger, respectively.
Note 2: Only FIPS 186-type domain parameters is approved.
- MQV
- National Institute of Standards and Technology, Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography, Special Publication 800-56A Revision 3, April 2018.
- Note 1: The length of the parameter p and q shall be 2048 bits or larger and 224 bits or larger, respectively.
Note 2: Only FIPS 186-type domain parameters is approved.
- ECDH
- National Institute of Standards and Technology, Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography, Special Publication 800-56A Revision 3, April 2018.
- Note: The length of the order of the elliptic curve shall be 224 bits or larger.
- ECDH
- SEC 1: Elliptic Curve Cryptography (May 21, 2009 Version 2.0)
- Note: The length of the order of the elliptic curve shall be 224 bits or larger.
- ECMQV
- National Institute of Standards and Technology, Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography, Special Publication 800-56A Revision 3, April 2018.
- Note: The length of the order of the elliptic curve shall be 224 bits or larger.
- Key Establishment Schemes in NIST SP800-56B
- KDF
- KDF
- National Institute of Standards and Technology, Recommendation for Key Derivation Using Pseudorandom Functions (Revised), Special Publication 800-108, October 2009.
- Note: KDF using Triple-DES is disallowed after December 31, 2019.
- KDF
- KDF
- National Institute of Standards and Technology, Recommendation for Existing Application-Specific Key Derivation Functions, Special Publication 800-135 Revision 1, December 2011.
- Note: KDF based on TPM and KDF for TLS1.0 and TLS1.1 are excluded.
Contact information
For further information, contact to:
IT Security Center, Information-technology Promotion Agency, Japan
-
E-mail

Change log
-
Nov 12, 2024
Contact Information is updated.
-
Jul 1, 2023
The old specifcation of Approved Security Functions, valid until June 30, 2023, is deleted.
-
Dec 21, 2022
The list of Approved Security Functions is corrected.
-
Aug 22, 2022
The list of Approved Security Functions is updated.
-
Sep 21, 2021
Reference URLs are updated.
-
Jan 8, 2020
The list of Approved Security Functions is updated.
-
Jul 19, 2019
The list of Approved Security Functions is updated.
-
Jun 27, 2018
The list of Approved Security Functions is updated.
-
Jul 24, 2014
The list of Approved Security Functions is updated.
-
Oct 7, 2013
Reference URLs are updated.
