6.4.4 Are digital signature applications exportable from the United States?

Digital signature applications are one of the nine special categories of cryptography that automatically fall under the more relaxed Commerce regulations; digital signature implementations using RSA key sizes in excess of 512 bits were exportable even before the year 2000. However, there were some restrictions when developing a digital signature application using a reversible algorithm (that is, the signing operation is sort of the reverse operation for encryption), such as RSA. In this case, the application should sign a hash of the message, not the message itself. Otherwise, the message had to be transmitted with the signature appended. If the message was not transmitted with the signature, the NSA considered this quasi-encryption and the State controls would apply.

