Cryptography API: Next Generation
Windows Vista features an update to the Crypto API known as Cryptography API: Next Generation (CNG). It has better API factoring to allow the same functions to work using a wide range of cryptographic algorithms, and the inclusion of a number of newer algorithms that are part of the National Security Agency (NSA) Suite B. It is also flexible, featuring support for plugging in custom cryptographic APIs into the CNG runtime. However, CNG Key Storage Providers still do not support symmetric keys. CNG works in both user and kernel mode, and also supports all of the algorithms from the CryptoAPI. The Microsoft provider that implements CNG is housed in Bcrypt.dll.
CNG also supports elliptic curve cryptography which is also secure and uses shorter keys than RSA. The CNG API integrates with the smart card subsystem by including a Base Smart Card Cryptographic Service Provider (Base CSP) module which encapsulates the smart card API. Smart card manufacturers just have to make their devices compatible with this, rather than provide a from-scratch solution.
CNG also adds support to Dual EC DRBG, a pseudorandom number generator defined in NIST SP 800-90 that could expose the user to eavesdropping by the National Security Agency unless the user remembers to generate new random numbers with a different cryptographically secure pseudorandom number generator or a true random number generator and then publishing the generated seed in order to make it secure. It is also very slow. It is only used when called for explicitly.
CNG also replaces the default PRNG with CTR_DRBG using AES as the block cipher, because the earlier RNG which is defined in the now superseded FIPS 186-2 is based on either DES or SHA-1, both which have been broken. CTR_DRBG is one of the two algorithms in NIST SP 800-90 endorsed by Schneier, the other being Hash_DRBG.
Read more about this topic: Microsoft Crypto API
Famous quotes containing the word generation:
“What makes this Generation of Vermin so very Prolifick, is the indefatigable Diligence with which they apply themselves to their Business. A Man does not undergo more watchings and fatigues in a Campaign, than in the Course of a vicious Amour. As it is said of some Men, that they make their Business their Pleasure, these Sons of Darkness may be said to make their Pleasure their Business. They might conquer their corrupt Inclinations with half the Pains they are at in gratifying them.”
—Joseph Addison (16721719)