CHANGES IN US CRYPTOGRAPHY POLICY

In last week's BillWatch (Issue #14) we described the background surrounding the announcement of the government's new "Key Escrow" proposal. Details are still sketchy, probably because they haven't been worked out yet. However detractors are calling the plan "Son of Clipper" while proponents are hoping it will strike a balance between industry, law enforcement, and the public.

NIST has distributed two discussion drafts to guide presentations on the workshops on Sep. 6th and 7th. Because this is not a public-friendly process (few of your elected representatives are likely to be involved in this process) we have re-published these papers here for your perusal.

VTW would like to publicly thank NIST for providing this information.


Key Escrow Issues Meeting, September 6-7, 1995
Discussion Paper #1

Issues -- Export of Software Key Escrowed Encryption

On August 17, 1995, the Administration announced its proposal to permit the ready export of software encryption provided that the products use algorithms with key space that does not exceed 64 bits and the key(s) required to decrypt messages/files are escrowed with approved escrow agents. Under the proposal, products will be reviewed to verify that they satisfy the criteria and, if so, they will be transferred to the Commodity Control List administered by the Department of Commerce where the products can be exported under a general license (in much the same way that 40-bit RC2/RC4 encryption is licensed today).

We are working toward creating broadly stated criteria that are in the nature of performance specifications. To meet these criteria, encryption products will need to implement key escrow mechanisms that cannot be readily altered or bypassed so as to defeat the purposes of key escrowing.

The criteria, when finalized and published, will state the objectives, but not the exact technical method(s), by which those objectives are satisfied. This is to provide software publishers the flexibility to design methods for meeting our stated objectives in a manner that is compatible with the design of their products. There are, therefore, a number of questions we must work together to answer in order to draft effective criteria. These questions are:


With your input, we are hopeful that this effort will lead to definitive criteria, which will facilitate the development of exportable products and help minimize the time required to obtain export licenses. The Administration seeks to finalize such criteria and make formal conforming modifications to the export regulations before the end of 1995.

Note: These issues will be discussed at the Key Escrow Issues Meeting to be held September 6-7, 1995 (9:00 a.m. - 5:00 p.m.) at the National Institute of Standards and Technology (Gaithersburg, Maryland). The meeting will be open to the public, although seating is limited. Advance registration is requested, please contact Arlene Carlton on 301/975-3240, fax: 301/948-1784 or e- mail: carlton@micf.nist.gov.

8/25/94


Key Escrow Issues Meeting, September 6-7, 1995
Discussion Paper #2

Discussion Issues: Desirable Characteristics for Key Escrow Agents

In the government's recent announcement of its intent to allow the export of 64-bit software key escrow encryption products, one stipulation was that the keys would be escrowed with an approved key escrow agent.(

  • 1) Exactly what qualifications/considerations are appropriate for approval as a key escrow agent have not been defined. Some of the issues which need to be discussed and resolved include the following:
    (*1) "Approved," for the purposes of this discussion, means that the government (or its agent) has formally granted permission for an organization to hold keys for exportable encryption products.

    Note: These issues will be discussed at the Key Escrow Issues Meeting to be held September 6-7, 1995 (9:00 a.m. - 5:00 p.m.) at the National Institute of Standards and Technology (Gaithersburg, Maryland). The meeting will be open to the public, although seating is limited. Advance registration is requested, please contact Arlene Carlton on 301/975-3240, fax: 301/948-1784 or e-mail: carlton@micf.nist.gov.

    8/25/95


    Abstraced from :

    VTW BillWatch: A weekly newsletter tracking US Federal legislation affecting civil liberties. BillWatch is published every Friday evening as long as Congress is in session.

    Issue #15, Date: Sat Aug 26 15:07:25 EDT 1995

    Please widely redistribute this document with this banner intact Redistribute no more than two weeks after above date Reproduce this alert only in relevant forums

    Distributed by the Voters Telecommunications Watch (vtw@vtw.org)

          *** Know of someone ANYWHERE with a fax machine but without net ***
          *** access that's interested in VTW's issues?  Tell them to     ***
          *** call and get on our weekly fax distribution list at         ***
          *** (718) 596-2851 (or email us their fax number.               ***
    

    To get on the distribution list for BillWatch, send mail to listproc@vtw.org with "subscribe vtw-announce Firstname Lastname" in the subject line.

    Email vtw@vtw.org with "send billwatch" in the SUBJECT LINE to receive the latest version of BillWatch

    For permission to reproduce VTW alerts contact vtw@vtw.org


    From:
    Date: Sat, 26 Aug 1995 16:04:40 -0400
    From: farber@central.cis.upenn.edu (David Farber)
    Subject: CHANGES IN US CRYPTOGRAPHY POLICY -- see end for credit
    Precedence: list
    To: interesting-people@eff.org (interesting-people mailing list)
    

    Last updated 95/08/28