Hi,
This NIST SP800-133 spec is finally being revised to align with updated
NIST SP800-90A/B/C
(Entropy and RNGs) and NIST PQC standards (FIPS 203, 204, 205 and future
206 and 207).
Crypto Key Generation underlies a whole lot of NIST specs. They have said
that SP800-133
will go to full standard in the next release in later 2026.
Cheers,
- Ira
---------- Forwarded message ---------
From: 'Hamilton Silberg' via pqc-forum <pqc-forum at list.nist.gov>
Date: Fri, Apr 17, 2026 at 9:54 AM
Subject: [pqc-forum] Call for comments: ipd SP 800-133r3 Recommendation for
Cryptographic Key Generation
To: pqc-forum <pqc-forum at list.nist.gov>
Hello all,
The initial public draft (ipd) of NIST SP 800-133r3 (Revision 3),
Recommendation for Cryptographic Key Generation, is available for public
comment.
Proposed changes in this revision include the following:
• Asymmetric key-pair generation has been expanded to include methods for
deriving randomness during key-pair generation.
• Key-pair generation now has options for derivation similar to symmetric
keys and new methods for “seed expansion,” which allows for the limited use
of SHAKE and deterministic random bit generators (DRBGs).
• Key-encapsulation mechanisms (KEMs) are discussed as a key-establishment
option for symmetric key generation, and post-quantum cryptography (PQC)
references have been added throughout (e.g., the new PQC signatures).
• Text has been reworded to address random number generation in alignment
with SP 800-90C.
Comments are especially requested regarding:
• Hardware security module (HSM) design — How do these requirements align
with common practice and existing systems using a root seed/secret value?
• PQC implementations and protocols — How do these requirements fit with
storing keys as seeds (e.g., for ML-KEM) and performing hybrid (i.e.,
combined classical and post-quantum) implementations?
The public comment period will be open through June 16, 2026.
See: https://csrc.nist.gov/pubs/sp/800/133/r3/ipd
Best,
-Hamilton Silberg
NIST PQC
--
You received this message because you are subscribed to the Google Groups
"pqc-forum" group.
To unsubscribe from this group and stop receiving emails from it, send an
email to pqc-forum+unsubscribe at list.nist.gov.
To view this discussion visit
https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/eb4929b9-119e-4f8f-a221-04976ea72d51n%40list.nist.gov
<https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/eb4929b9-119e-4f8f-a221-04976ea72d51n%40list.nist.gov?utm_medium=email&utm_source=footer>
.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://www.pwg.org/pipermail/ipp/attachments/20260507/f17a21a9/attachment.html>