CKM_DES3_ECB_PAD

Supported Operations

Encrypt and Decrypt

Yes

Sign and Verify

No

SignRecover and VerifyRecover

No

Digest

No

Generate Key/Key-Pair

No

Wrap and Unwrap

Yes (unwraps existing data only; cannot wrap new data)

Derive

No

FIPS-approved

Yes (decrypt existing data only; cannot encrypt new data)

Key Size Range (bytes) and Parameters

Minimum 16
FIPS Minimum 16
Maximum 24
Parameter None

Description

This is a padding mechanism. Implemented padding mechanisms are:

>CKM_CAST128_ECB_PAD

>CKM_DES_ECB_PAD

>CKM_DES3_ECB_PAD

>CKM_IDEA_ECB_PAD

>CKM_RC2_ECB_PAD

These block cipher mechanisms are all based on the corresponding Electronic Code Book (ECB) algorithms, implied by their name, but with the addition of the block-cipher padding method detailed in PKCS#7.

These mechanisms are supplied for compatibility only and their use in new applications is not recommended.

PKCS#11 version 2.20 specifies mechanisms for Chain Block Cipher algorithms with and without padding and ECB algorithms without padding, but not ECB with padding.  These mechanisms fill this gap. The mechanisms may be used for general data encryption and decryption and also for key wrapping and unwrapping (provided all the access conditions of the relevant keys are satisfied).

Return to SafeNet ProtectToolkit-C Mechanisms