National Bureau of Standards (NBS) ~ 1901-1988
National Institute of Standards and Technology (NIST) ~ 1988 to Present
Updated March 21, 2025
After great demand from US scientists and industrialists to establish an authoritative domestic measurement and standards laboratory, the US Congress founded National Bureau of Standards (NBS) on March 3, 1901. Prior to NBS’s inception, it was widely believed that the US had a second-rate measuring system that needed standardization in order for the US to be competitive with the United Kingdom, Germany, and other economic rivals. Renamed in 1988, NBS became the National Institute of Standards and Technology (NIST), which is now part of the US Department of Commerce and is one of the nation’s oldest physical science laboratories.
Most people are not aware of the scope of technology NIST oversees. In the gangster era of Prohibition and the Great Depression, a physicist at then NBS, brought modern ideas to the merging field of forensic science. Today, everything from the smart electric power grids, to electronic health records, atomic clocks, advanced nanomaterials, computer chips, and innumerable additional products and services rely in some way on technology, measurement, and standards, provided by the National Institute of Standards and Technology.
NIST measurements support the smallest of technologies to the largest and most complex of human-made creations, from nanoscale devices so tiny that tens of thousands can fit on the end of a single human hair, up to earthquake-resistant skyscrapers and global communication networks. [1]
NIST’s interest in cryptology began in 1972 when it started conducting cybersecurity research and developed cybersecurity guidance for industry, government, and academia. [2] In early 1973, after IBM had successfully created their own block cipher encryption technology called Lucifer, NBS put out a request for proposals for creating a block cipher that would become a national standard. Before that time, cryptography had been largely the concern and responsibility of military and intelligence organizations. This was the first Federal Government project to develop a publicly available cryptographic standard to satisfy a broad range of requirements. [3]
IBM’s Lucifer was eventually accepted by NBS, describing it as Data Encryption Standard (DES), and issued as Federal Information Processing Standard (FIPS) 46, on November 23, 1977.
In the 1997, DES was broken by an exhaustive search attack. The main problem with DES was the small size of the encryption key. As computing power increased it became easy to brute force attack all different combinations of the key to obtain a possible plain text message. [4]
The establishment of DES was not without controversy. It was known that the National Security Agency (NSA) had worked with NBS throughout the DES development, evaluated the proposed algorithm, and recommended several changes. IBM modified the algorithm based on these recommendations. Some critics suspected that NSA had deliberately weakened the algorithm or perhaps even introduced a “trap door” into the specification that would enable the intelligence community to decrypt messages. Another controversy involved the key length. A commonly accepted requirement is that no attack to obtain the plaintext must exist that is more efficient than trying all possible keys. Critics argued that the effective DES key length of 56 bits (64-bit key minus 8 checksum bits) was too short for long-term security, and that expected increases in computer power would soon make a 56-bit key length vulnerable to attack by key exhaustion. One source of this was Exhaustive Cryptanalysis of the NBS Data Base Encryption Standard from Whitfield Diffie and Martin E. Hellman in Computer magazine in 1977. NBS responded that the standard was adequate against any practical attack for the anticipated life of the standard (15 years) and would be reviewed for adequacy every five years. [5] DES lasted almost exactly 20 years, from 1977 to 1997.
With the realization that the security strength of DES would soon be overtaken by cryptanalysis improvements, in 1997, NIST initiated the first world-wide public competition to solicit a 128-bit block cipher with three key length options: 128, 192, and 256 bits. This open competition enabled NIST to partner with an international community of cryptographers, academic researchers and industry practitioners. It received 50 submissions, and in 2000, it accepted an encryption titled Rijndael, which was coined the Advanced Encryption Standard (AES). Today AES is a widely accepted standard used for symmetric encryption. [6]
In April 2010, NIST published NIST SP 800-22rev1a (dated April 2010), A Statistical Test Suite for the Validation of Random Number Generators and Pseudo Random Number Generators for Cryptographic Applications. Random Number Generators (RNGs) are an important building block for algorithms and protocols in cryptography. They are paramount in the construction of encryption keys and other cryptographic algorithm parameters. In practice, statistical testing is employed to gather evidence that a generator indeed produces numbers that appear to be random. Few resources are readily available to researchers in academia and industry who wish to analyze their newly developed RNG. [7]
NIST’s test suite consists of 16 different tests that can be used to determine whether a hardware or software-based cryptography number is considered to be pseudo-random, meaning there are no discernable patterns of numbers or zeros and ones within the binary sequence being tested.
Additionally, NIST offers a suite of 9 downloadable pseudo-random number generators, that cryptographers and developers can use in their hardware and software technologies.
JumPedal’s CipherBolt encryption software has 15 (the 16th did not apply to our program’s formatting) of NIST’s test suite embedded within their cryptographic process. If a generated key does not pass all 15 NIST tests, the number is regenerated and retested until it passes all 15 test requirements. Although there is no possible way to determine whether a number is truly random, and some will argue that there is no such thing as a random number, JumPedal believes these are the best tools currently available.
NIST Pre-Quantum Computer Cybersecurity:
Recognizing that cybersecurity was a top national security concern, on February 12, 2013, President Obama signed Executive Order 13636, Improving Critical Infrastructure Cybersecurity. This Executive Order was designed to increase the level of core capabilities for our critical infrastructure to manage cyber risk. It does this by focusing on three key areas: (1) information sharing, (2) privacy, and (3) the adoption of cybersecurity practices. The Executive Order tasked NIST to work with the private sector to identify existing voluntary consensus standards and industry best practices and build them into a Cybersecurity Framework. [8]
In response to the Obama Executive Order, NIST initiated a standardization process by announcing a call for proposals. It is intended that the new public-key cryptography standards will specify one or more additional unclassified, publicly disclosed digital signature, public-key encryption, and key-establishment algorithms that are available worldwide, and are capable of protecting sensitive government information well into the foreseeable future, including after the advent of quantum computers. [9]
One year after the release of Executive Order 13636, on February 12, 2014, NIST released version 1.0 of the Framework for Improving Critical Infrastructure Cybersecurity. The Framework was released as voluntary guidance, based on existing standards, guidelines, and practices, for critical infrastructure organizations to better manage and reduce cybersecurity risk. [10]
In 2017, a draft version of the framework, version 1.1, was circulated for public comment. [11]
Post-Quantum Computer (PQC) Cybersecurity:
In December 2016, NIST issued a public call for submissions to the PQC Standardization Process.
Below is a timeline of candidate selection:
- First Round 2017 – 69 candidates chosen
- Second Round 2019 – 26 surviving candidates
- Third Round 2020 – 7 finalists, 8 alternates
- Fourth Round 2022 – 3 finalists and 1 alternate selected as standards. [12]
In July 2023, NIST announced the first four winners from its six-year competition. This first group of encryption tools chosen are “designed to withstand the assault of a future quantum computer, which could potentially crack the security used to protect privacy in the digital systems we rely on every day, such as online banking and email software. The four selected encryption algorithms will become part of NIST’s post-quantum cryptographic standard, expected to be finalized and ready for public release for use, in about two years.”
NIST went on to specify that for general encryption, used when we access secure websites, NIST selected the CRYSTALS-Kyber algorithm. Among its advantages are comparatively small encryption keys that two parties can exchange easily, as well as its speed of operation.
And for digital signatures, often used when we need to verify identities during a digital transaction or to sign a document remotely, NIST selected the three algorithms CRYSTALS-Dilithium, FALCON and SPHINCS+. Reviewers noted the high efficiency of the first two, and NIST recommends CRYSTALS-Dilithium as the primary algorithm, with FALCON for applications that need smaller signatures than Dilithium can provide. The third, SPHINCS+, is somewhat larger and slower than the other two, but it is valuable as a backup for one chief reason: It is based on a different math approach than all three of NIST’s other selections. [13]
In August of 2024, NIST released a final set of encryption tools designed to withstand the attack of a quantum computer, stating that “these three post-quantum encryption standards secure a wide range of electronic information, from confidential email messages to e-commerce transactions that propel the modern economy.” NIST is encouraging computer system administrators to begin transitioning to the new standards as soon as possible.
While there have been no substantive changes made to the standards since the draft versions, NIST has changed the algorithms’ names to specify the versions that appear in the three finalized standards, which are:
- Federal Information Processing Standard (FIPS) 203, intended as the primary standard for general encryption. Among its advantages are comparatively small encryption keys that two parties can exchange easily, as well as its speed of operation. The standard is based on the CRYSTALS-Kyber algorithm, which has been renamed ML-KEM, short for Module-Lattice-Based Key-Encapsulation Mechanism.
- FIPS 204, intended as the primary standard for protecting digital signatures. The standard uses the CRYSTALS-Dilithium algorithm, which has been renamed ML-DSA, short for Module-Lattice-Based Digital Signature Algorithm.
- FIPS 205, also designed for digital signatures. The standard employs the Sphincs+ algorithm, which has been renamed SLH-DSA, short for Stateless Hash-Based Digital Signature Algorithm. The standard is based on a different math approach than ML-DSA, and it is intended as a backup method in case ML-DSA proves vulnerable.
Similarly, when the fourth draft FIPS 206 standard built around FALCON is released, the algorithm will be dubbed FN-DSA, short for FFT (fast-Fourier transform) over NTRU-Lattice-Based Digital Signature Algorithm. [14]
In March of 2025, NIST announced that it has chosen a new algorithm for post-quantum encryption called HQC, which will serve as a backup for ML-KEM, the main algorithm for general encryption. HQC is based on different math than ML-KEM, which could be important if a weakness were discovered in ML-KEM.
NIST plans to issue a draft standard incorporating the HQC algorithm in about a year, with a finalized standard expected in 2027. [15]
[1] nist.gov/history
[2] csrc.nist.gov/nist-cyber-history
[3] src.nist.gov/nist-cyber-history/cryptography/chapter
[4] rsaconference.com/library/blog/brute-force-cracking-the-data-encryption-standard
[5] csrc.nist.gov/nist-cyber-history/cryptography/chapter
[6] nist.gov/blogs/cybersecurity-insights/cornerstone-cybersecurity-cryptographic-standards-and-50-year-evolution
[7] nist.gov/publications/statistical-testing-random-number-generators
[8] obamawhitehouse.archives.gov/issues/foreign-policy/cybersecurity/eo-13636
[9] nist.gov/news-events/news/2016/12/nist-asks-public-help-future-proof-electronic-information
[10] cybersecurity-framework-021214
[11] csf-manufacturing-profile-draft2
[12] theregister.com/2022/07/05/nist_quantum_resistant_algorithms/
[13] nist.gov/news-events/news/2022/07/nist-announces-first-four-quantum-resistant-cryptographic-algorithms#:~:text=The algorithms are designed for two main,experts collaborating from multiple countries and institutions.
[14] nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards#:~:text=GAITHERSBURG%2C Md. — The U.S. Department of,to withstand cyberattacks from a quantum computer.
[15] https://www.nist.gov/news-events/news/2025/03/nist-selects-hqc-fifth-algorithm-post-quantum-encryption








