Building on our history of cryptographic research
The NCSC has published new cryptographic research on robust cryptography – we explain its significance and how the ideas could support research to inform future global standards.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
The NCSC has published new cryptographic research on robust cryptography – we explain its significance and how the ideas could support research to inform future global standards.

Our organisation has a long history of cryptographic research. As the UK national technical authority for cryptography, the NCSC provides consultancy on cryptography for government use cases, as well as publishing guidance for other organisations and the public. We also carry out research, and design cryptographic algorithms.
Cryptography is a part of our work you don’t hear much about, but it’s crucial to the wider NCSC mission to make the UK the safest place to live and work online. One element of this is our work to secure public and private sector networks. This brings in many complex cyber security measures and one of them is cryptographic protection of the data held and communicated on them.
This is where our recently published work comes in.
We’ve just published a paper for the cryptographic community in which we release two new designs for cryptographic algorithms known as block cipher modes of operation, or ‘modes’. We’re also sharing the supporting security analysis and design rationale. We’ve named the new modes GLEVIAN and VIGORNIAN*.
What is the significance of this work? Well, one way that cryptographic risk to the nation’s networks can manifest is through accidental misuse of that cryptography – algorithms that are secure when used correctly but can be vulnerable when they are used in ways the designers didn’t intend.
The novelty in our research is a particular combination of strong robustness properties in the designs, meaning that cryptographic security is maintained even in the event of significant human error in their deployment or use. This robustness helps build assurance into the design and development of systems, in line with the principles of security by design and default, a key aim of modern cyber security practice.
Designing cryptographic systems – and the protocols they rely on – to be as resilient as possible is widely recognised as an important thing. In the US, the National Institute of Standards and Technology (or NIST, part of the US Department of Commerce) maintains various standards for cryptography that are widely used across the world. One of their current initiatives is a process to update the cryptographic standards for modes, which is partly motivated by a desire for more robust algorithms.
We really support the NIST aim to standardise new modes, and our cryptography research team has been studying modes for several years. Our work on these two new modes adds to the fundamental research that future standards can draw on.
In the NCSC, we design cryptography principally for use cases where long-term security is required, or where data has some sensitivity to it, so we take a very risk-averse approach to its handling. The security requirements we design for are common to use cases in many commercial organisations – but of course not all cryptographers will make the same prioritisation decisions as us in their designs. For example, we usually prefer to keep designs as simple as possible, even if that comes at some cost in performance.
We believe our designs will be of interest to those with use cases similar to ours and our paper also suggests directions for future research – we’d be very happy to see others build on our work. And if you’re interested in the detail and want to see the paper, a reminder that you can find it on the International Association for Cryptologic Research website.
* If you’re wondering about the origin of these names, they resemble the Roman names for the cities of Gloucester (Glevum) and Worcester (Vigornia), both close to Cheltenham where the NCSC has a large presence. We have then additionally styled them to sound similar to the names of musical modes.

