Strong Cryptography

PCIComplianceHubLast updated

Cryptography based on algorithms and key lengths that are industry-tested and accepted, with effective key management behind them. PCI DSS treats a minimum of 112 bits of effective key strength as the threshold, which in practice means AES-128 or above, RSA-2048 or above, and TLS 1.2 or higher for data in transit. The term covers more than algorithm choice: an approved algorithm used with weak keys, a poor mode of operation or careless key storage is not strong cryptography. SSL, early TLS, DES and SHA-1 for signatures no longer qualify.