ISO/IEC 11770-5:2020
Information security — Key management — Part 5: Group key management
Information security — Key management — Part 5: Group key management
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 18
- Дата публикации:
- 10 ноября 2020 г.
- Издание:
- ISO/IEC IS 11770 edition 2 version 1
- ICS:
- 35.030
This document specifies mechanisms to establish shared symmetric keys between groups of entities. It defines: — symmetric key-based key establishment mechanisms for multiple entities with a key distribution centre (KDC); and — symmetric key establishment mechanisms based on a general tree-based logical key structure with both individual rekeying and batch rekeying. It also defines key establishment mechanisms based on a key chain with group forward secrecy, group backward secrecy or both group forward and backward secrecy. This document also describes the required content of messages which carry keying material or are necessary to set up the conditions under which the keying material can be established. This document does not specify information that has no relation with key establishment mechanisms, nor does it specify other messages such as error messages. The explicit format of messages is not within the scope of this document. This document does not specify the means to be used to establish the initial secret keys required to be shared between each entity and the KDC, nor key lifecycle management. This document also does not explicitly address the issue of interdomain key management.
Abstract
Overview
ISO/IEC 11770-5:2020 - Information security - Key management - Part 5: Group key management specifies standardized mechanisms for establishing shared symmetric keys among groups of entities. The standard focuses on group key establishment with the assistance of a Key Distribution Centre (KDC) and on logical key structures (tree-based) and key chains that provide group forward secrecy, group backward secrecy, or both. It describes the required content of messages that carry keying material and defines rekeying approaches; it does not prescribe explicit message formats, initial secret provisioning, key lifecycle management, or interdomain key management.
Key topics and technical requirements
- KDC-based symmetric key mechanisms: procedures to distribute shared secret keys from a trusted KDC to multiple entities.
- Logical key hierarchies / tree-based structures: general tree, d-ary trees, and star topologies to organise key encryption keys (KEKs), ancestor/child keys, and the shared secret key.
- Rekeying methods:
- Individual rekeying - update keys immediately when a member joins or leaves, providing group forward and backward secrecy.
- Batch rekeying - periodic updates using interval T, providing forward/backward secrecy with intervals (trade-off between performance and security).
- Key chain approaches: forward, backward, or combined secrecy using one-way functions to derive sequences of keys.
- Security properties: clear definitions of group forward secrecy, group backward secrecy, and forward/backward secrecy with intervals; selection depends on application security policy.
- Message content: required fields for messages that carry keying material (content specified; explicit encoding/out-of-scope).
- Cryptographic primitives: symmetric encryption algorithms and key derivation functions referenced (normative references include ISO/IEC 19772 and ISO/IEC 11770-6).
Practical applications
ISO/IEC 11770-5 is applicable to systems that require securely shared symmetric keys for group communication, including:
- Secure multicast and broadcast services
- Conferencing and collaborative platforms (VoIP, video conferencing)
- Group messaging and secure chat systems
- IoT device groups and edge computing clusters
- Enterprise group access control and distributed services
The standard helps architects balance security (immediate rekeying) versus scalability and performance (batch rekeying or tree-based KEK pruning).
Who should use this standard
- Security architects and protocol designers building group key management
- System integrators implementing KDC-based or hierarchical key systems
- Product teams for secure conferencing, IoT platforms, and multicast services
- Standards compliance and security assessment professionals
Related standards
- ISO/IEC 19772 - Authenticated encryption primitives (referenced for symmetric encryption)
- ISO/IEC 11770-6 - Key derivation (used for key derivation function specifications)
Keywords: ISO/IEC 11770-5:2020, group key management, KDC, tree-based key establishment, key chain, group forward secrecy, group backward secrecy, rekeying, symmetric key.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 11770-5:2020
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS ISO/IEC 19772:2020
ДействующийInformation security. Authenticated encryption.
BS ISO/IEC 11770-5:2020
ДействующийInformation security. Key management. Group key management.
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…