{"id":100135,"date":"2018-11-05T07:00:00","date_gmt":"2018-11-05T22:00:00","guid":{"rendered":"https:\/\/blogs.msdn.microsoft.com\/oldnewthing\/?p=100135"},"modified":"2019-03-13T00:13:47","modified_gmt":"2019-03-13T07:13:47","slug":"20181105-00","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/oldnewthing\/20181105-00\/?p=100135","title":{"rendered":"Sure, you can implement your own cryptographic service provider for a standard algorithm, but why would you?"},"content":{"rendered":"<p>A customer wanted to write their own custom implementation of an existing standard encryption algorithm. The customer liaison noted that this custom implementation would presumably produce results identical to the built-in implementation because it is, after all, a standard. But if that&#8217;s the case, there doesn&#8217;t seem to be much point to the undertaking. <\/p>\n<p>There was some speculation as to why the customer wanted to reimplement a standard algorithm. Maybe they thought they could do a better job by taking advantage of <a HREF=\"https:\/\/en.wikipedia.org\/wiki\/AES_instruction_set\">special-purpose instructions in the CPU<\/a> for encryption and decryption? But a member of the security team confirmed that the built-in providers already take advantage of those instructions if available. &#8220;Unless your customer wants to use a mode that the built-in providers don&#8217;t support, there is no technical reason for them to write their own implementation.&#8221; <\/p>\n<p>The customer liaison reported that the customer was trying to close a deal with a client. The client wants to be able to <a HREF=\"http:\/\/technet.microsoft.com\/en-us\/library\/dn554259%28v=exchg.150%29.aspx\">configure Exchange to use a customized encryption algorithm<\/a>. &#8220;They might not end up creating such a customized encryption algorithm, but they want to be sure that it&#8217;s possible, so they need a proof-of-concept demonstration.&#8221; The customer found the <a HREF=\"http:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=30688\">Cryptographic Provider Development Kit<\/a> and was working through the sample provider. <\/p>\n<p>One person contributed to the discussion with a story from personal experience: <\/p>\n<blockquote CLASS=\"q\"><p>I worked at a company where custom cryptography was a government requirement. Don&#8217;t do it. Developing and supporting custom cryptography is a multi-year undertaking. <a HREF=\"http:\/\/www.cryptopro.ru\/products\/csp\">It is technically possible<\/a>, but I don&#8217;t think your customer is willing to invest so much. You need to position the solution differently. <\/p><\/blockquote>\n<p><a HREF=\"https:\/\/blogs.msdn.microsoft.com\/aaron_margosis\/\">Aaron Margosis<\/a> agreed. &#8220;Sometimes, people take technical requirements too literally when they should be looking at the bigger-picture business requirement, which can often be met with existing technologies.&#8221; <\/p>\n","protected":false},"excerpt":{"rendered":"<p>You are signing up for a very big world of hurt.<\/p>\n","protected":false},"author":1069,"featured_media":111744,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[26],"class_list":["post-100135","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-oldnewthing","tag-other"],"acf":[],"blog_post_summary":"<p>You are signing up for a very big world of hurt.<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/100135","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/users\/1069"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/comments?post=100135"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/100135\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/media\/111744"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/media?parent=100135"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/categories?post=100135"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/tags?post=100135"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}