CACrown ArchivesThe cinema collection
Menu
Research dossier · Places & Architecture

BSAFE

cryptography library

Architectural plans, a scale model, maps and brass measuring instruments
Places and architectureInterpretive dossier study · Crown Archives visual atlas
Record originEnglish Wikipedia
Text licenseCC BY-SA 4.0
Source revisionJul 15, 2026
Entity authorityQ17083990
Source-derived summary

Dell BSAFE, formerly known as RSA BSAFE, is a FIPS 140-2 validated cryptography library, available in both C and Java. BSAFE was initially created by RSA Security, which was purchased by EMC and then, in turn, by Dell. When Dell sold the RSA business to Symphony Technology Group in 2020, Dell elected to retain the BSAFE product line. BSAFE was one of the most common encryption toolkits before the RSA patent expired in September 2000. It also contained implementations of the RCx ciphers, with the most common one being RC4. From 2004 to 2013 the default random number generator in the library was a NIST-approved RNG standard, widely known to be insecure from at least 2006, containing a kleptographic backdoor from the American National Security Agency (NSA), as part of its secret Bullrun program. In 2013 Reuters revealed that RSA had received a payment of $10 million to set the compromised algorithm as the default option. The RNG standard was subsequently withdrawn in 2014, and the RNG removed from BSAFE beginning in 2015.

Cryptography backdoors

Dual_EC_DRBG random number generator

From 2004 to 2013, the default cryptographically secure pseudorandom number generator (CSPRNG) in BSAFE was Dual_EC_DRBG, which contained an alleged backdoor from NSA, in addition to being a biased and slow CSPRNG. The cryptographic community had been aware that Dual_EC_DRBG was a very poor CSPRNG since shortly after the specification was posted in 2005, and by 2007 it had become apparent that the CSPRNG seemed to be designed to contain a hidden backdoor for NSA, usable only by NSA via a secret key. In 2007, Bruce Schneier described the backdoor as "too obvious to trick anyone to use it." The backdoor was confirmed in the Snowden leaks in 2013, and it was insinuated that NSA had paid RSA Security US$10 million to use Dual_EC_DRBG by default in 2004, though RSA Security denied that they knew about the backdoor in 2004.

Editorial summary

“BSAFE” enters the record as cryptography library. Crown Archives preserves that source wording while asking what BSAFE, cryptography and library can confirm, complicate or overturn.

Editorial reviewMost useful as a place-based finding aid connecting the present description to earlier jurisdictions, maps and built evidence. The current lead gives the account dated anchors—2020, 2000, 2004, 2013—that can be checked directly. The selected authority fields contribute no independent date. Its strongest next move is a source search built around BSAFE, cryptography and library.
Editorial analysis

Why this record matters

“BSAFE” is worth following because a concise public description often conceals a longer documentary argument. Here, BSAFE, cryptography and library provides the most credible route into that argument.

Evidence profile

The strongest evidence will usually combine a dated visual record with documents produced by the authority responsible for the place. The source revision retrieved here is dated Jul 15, 2026. The linked authority identifier is Q17083990. None of the 0 selected statements returned an explicit reference. The first chronological checks are 2020, 2000, 2004 and 2013.

Critical limits

A single description cannot reconcile every naming convention, rebuilding phase or administrative transfer associated with a place. The source lead contains qualifying language; that uncertainty should survive quotation, summary and reuse. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.

How to read it

Treat names, boundaries and functions as historically changeable. Maps, plans, inventories and administrative records can clarify what the place meant at different dates.

Best used for
  • Historic place names
  • Jurisdictional context
  • Routes into maps and plans
Verify next

Contemporary maps, plans, listed-building records, estate papers and the responsible local or national archive.

Three-step research path

  1. Establish the record: confirm the title “BSAFE”, its source revision and the description used here.
  2. Expand the search: follow BSAFE primary sources, BSAFE archive and BSAFE research across catalogues and specialist indexes.
  3. Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.

Questions for further research

  1. Which source most directly establishes the central claim about “BSAFE”?
  2. Which authority defined the place, boundary or structure at the relevant date?
  3. Which earlier names or jurisdictions may reveal additional records?
Subject index

Search terms from this dossier

Source & attribution

This entry incorporates text from BSAFE” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.