ISO/IEC 11770-2:2018
IT Security techniques — Key management — Part 2: Mechanisms using symmetric techniques
IT Security techniques — Key management — Part 2: Mechanisms using symmetric techniques
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 28
- Дата публикации:
- 28 сентября 2018 г.
- Издание:
- ISO/IEC IS 11770 edition 3 version 1
- ICS:
- 35.030
This document defines key establishment mechanisms using symmetric cryptographic techniques. This document addresses three environments for the establishment of keys: Point-to-Point, Key Distribution Centre (KDC), and Key Translation Centre (KTC). It describes the required content of messages which carry keying material or are necessary to set up the conditions under which the keying material can be established. This document does not indicate other information which can be contained in the messages or specify other messages such as error messages. The explicit format of messages is not within the scope of this document. This document does not specify the means to be used to establish initial secret keys; that is, all the mechanisms specified in this document require an entity to share a secret key with at least one other entity (e.g. a TTP). For general guidance on the key lifecycle, see ISO/IEC 11770-1. This document does not explicitly address the issue of inter-domain key management. This document also does not define the implementation of key management mechanisms; products complying with this document are not necessarily compatible.
Abstract
Overview
ISO/IEC 11770-2:2018 - "IT Security techniques - Key management - Part 2: Mechanisms using symmetric techniques" defines standardized key establishment mechanisms using symmetric cryptography. The standard covers three operational environments for secure key setup: Point-to-Point, Key Distribution Centre (KDC) and Key Translation Centre (KTC). It specifies the required content of messages that carry keying material or set conditions under which keys are established, and describes 13 named mechanisms (mechanisms 1–13) for these environments.
Key topics and technical requirements
- Symmetric techniques: mechanisms use symmetric encryption, Message Authentication Codes (MACs) and Key Derivation Functions (KDFs) rather than public-key operations.
- Environments addressed:
- Point-to-Point key establishment (direct between entities).
- KDC-based distribution (centralized key distribution).
- KTC-based translation (central authority translates keys between domains).
- Message content: the standard defines required fields carrying keying material and time-variant parameters (random numbers, sequence numbers, timestamps - TVPs) to prevent replay and support key confirmation.
- Authentication and confirmation: mechanisms can provide entity authentication, implicit/explicit key authentication and key confirmation.
- Auxiliary material: annexes include object identifiers, properties of mechanisms and auxiliary techniques (e.g., format guidance), but explicit message encoding and transport formats are out of scope.
- Scope limitations: ISO/IEC 11770-2:2018 does not define how initial long‑term secrets are established, does not mandate message encoding, and does not explicitly address inter‑domain key management or implementation compatibility.
Practical applications and users
- Who uses it: security architects, cryptographic protocol designers, system integrators, product vendors, evaluators and auditors who implement or assess symmetric key management.
- Practical uses: designing secure session key distribution in closed systems, implementing KDC/KTC-based enterprise key services, specifying message contents for secure symmetric key exchange, and aligning product features with international best practices for symmetric key establishment.
- Benefits: ensures standardized message content, supports mutual authentication and key confirmation, and helps reduce protocol design errors when relying on symmetric primitives.
Related standards (brief)
- ISO/IEC 11770-1 - Key management framework and lifecycle guidance.
- ISO/IEC 9798 series - Entity authentication mechanisms (from which some symmetric key establishment methods are derived).
Keywords: ISO/IEC 11770-2:2018, key management, symmetric techniques, key establishment, KDC, KTC, point-to-point, KDF, MAC, key confirmation, cryptographic key lifecycle.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 11770-2:2018
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO/IEC 9798-2:2008
ОтменёнInformation technology — Security techniques — Entity authentication — Part 2: Mechanisms using symmetric enc…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…