ISO 16609:2022
Financial services — Requirements for message authentication using symmetric techniques
Financial services — Requirements for message authentication using symmetric techniques
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 13
- Дата публикации:
- 2 августа 2022 г.
- Издание:
- ISO IS 16609 edition 3 version 1
- ICS:
- 35.240.40
This document specifies procedures, independent of the transmission process, for protecting the integrity of transmitted financial-service-related messages and for verifying that a message has originated from an authorized source, or that stored data has retained integrity. A list of block ciphers approved for the calculation of a message authentication code (MAC) is also provided. The authentication methods defined in this document are applicable to stored data and to messages formatted and transmitted both as coded character sets or as binary data. This document is designed for use with symmetric algorithms where both sender and receiver use the same key. It does not specify methods for establishing the shared key. Its application will not protect the user against internal fraud perpetrated by the sender or the receiver, nor against forgery of a MAC by the receiver.
Abstract
Overview
ISO 16609:2022 - Financial services: Requirements for message authentication using symmetric techniques - defines procedures for protecting the integrity and authenticity of financial messages and stored financial data using symmetric key Message Authentication Codes (MACs). The standard is transmission‑process independent, specifies how to generate, place and verify MACs, and identifies approved authentication mechanisms based on the ISO/IEC 9797 series. It is designed for use where sender and receiver share the same key; it does not specify key establishment methods.
Key topics and requirements
- Message Authentication Codes (MACs): Requirements for MAC generation, recomputation and verification to detect accidental or deliberate message alteration.
- Symmetric techniques: Uses shared-secret authentication keys (both parties hold the same key); key handling must follow ISO 11568 principles.
- Message elements to protect: Guidance on which data elements should be included in MAC calculation - for example, transaction amount, currency, key identifier (IDA), payer/beneficiary identifiers, message identifier (MID), date/time, and transaction disposition.
- MAC placement: Options include adding a dedicated MAC field in the message, appending the MAC to the data portion, or retaining the MAC in unambiguous association with stored data.
- Duplication, loss and sequencing detection: Recommendations to include unique transaction references or MIDs, date MAC computed (DMC), or key-derivation per transaction to detect replay, loss or out‑of‑order messages.
- Approved mechanisms: The standard references and approves specific MAC mechanisms and hash functions from the ISO/IEC 9797 series and provides a list of approved block ciphers for MAC calculation (see the standard for the authoritative list).
- Limitations: ISO 16609 does not define key establishment, and its application does not prevent internal fraud by sender/receiver or MAC forgery by a receiver.
Practical applications
- Ensuring message integrity and origin authentication for payment messages, interbank transfers, card transaction messages, ledger backups, and other stored financial data.
- Integrating MAC-based protection in banking gateways, payment processors, host-to-host financial APIs, and transaction logging systems.
- Creating interoperable implementations between institutions for secure transaction exchange.
Who should use this standard
- Financial institutions, payment scheme operators, core banking vendors, payment processors, and security architects responsible for transaction integrity.
- Developers and auditors implementing or reviewing MAC-based message protection in symmetric cryptography environments.
Related standards
- ISO/IEC 9797 (MAC algorithms and hash function guidance)
- ISO 11568-1 / ISO 11568-2 (key management for retail banking)
- ISO 8583-1 (financial transaction message formats)
For implementation, consult ISO 16609:2022 for approved algorithms, detailed procedures, and Annexes (including a tutorial and MID protection guidance).
Технические детали
- Технический комитет
- ISO/TC 68/SC 2 - Financial Services, security
- SKU
- ISO 16609:2022
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 9797-3:2011
ДействующийInformation technology — Security techniques — Message Authentication Codes (MACs) — Part 3: Mechanisms using…
Overview ISO/IEC 9797-3:2011 - "Information technology - Security techniques - Message Authentication Codes (MACs) - Part 3: Mechanisms using a universal hash-function" - specifies MAC algorithms tha…