ISM-0480

3DES is used with three distinct keys.

Topic
Using the Triple Data Encryption Standard
Applicable to
Official, Protected

History

Priority
must
Dec 2021
Removed
In light of ASD’s guidance to transition to AES from 3DES (since the 2017 ISM release), NIST guidance deprecating existing 3DES use and prohibiting its use in new systems and applications, and attacks such as Sweet32 that can reduce 3DES security from 112 bits to 80 bits of effective security strength, ASD has re-assessed the suitability of 3DES for the ongoing protection of up to PROTECTED data. As a result of this assessment, 3DES will be retired as an ASD Approved Cryptographic Algorithm effective immediately.
2017
Agencies using 3DES must use three distinct keys.
Control Text Changed. No public explaination.
2015
Agencies using 3DES must use either two distinct keys in the order key 1, key 2, key 1 orthree distinct keys.
2010
3DES must use either two distinct keys in the order key 1, key 2, key 1 or three distinct keys.
2008
3DES must use either two distinct keys in the order key 1, key 2, key 1 or three distinct keys.