ISO/IEC 14888-1:2008
Information technology — Security techniques — Digital signatures with appendix — Part 1: General
Information technology — Security techniques — Digital signatures with appendix — Part 1: General
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 11
- Дата публикации:
- 1 апреля 2008 г.
- Издание:
- ISO/IEC IS 14888 edition 2 version 1
- ICS:
- 35.030
There are two types of digital signature mechanism: When the verification process needs the message as part of the input, the mechanism is called "signature mechanism with appendix". A hash-function is in used in the calculation of the appendix. When the verification process reveals all or part of the message, the mechanism is called a "signature mechanism giving message recovery". A hash-function is also used in the generation and verification of these signatures. ISO/IEC 14888 specifies digital signatures with appendix. ISO/IEC 14888-1:2008 specifies general principles and requirements for digital signatures with appendix. ISO/IEC 14888-2 addresses digital signatures based on integer factoring, and ISO/IEC 14888-3 addresses digital signatures based on discrete logarithm. Signature mechanisms giving message recovery are specified in ISO/IEC 9796. Hash-functions are specified in ISO/IEC 10118.
Abstract
Overview
ISO/IEC 14888-1:2008 specifies general principles and requirements for digital signatures with appendix - a class of asymmetric cryptographic mechanisms where the verifier requires the message as part of the verification input. The standard defines the model, terminology, and mandatory processes (key generation, signature process, verification process) and sets security objectives for signature mechanisms that use a collision-resistant hash-function to compute the appendix appended to a message.
Key topics and technical requirements
- Signature mechanism with appendix: Defines how a signature (the appendix) and optional text field are formed and attached to a message so verifiers can relate the signature to the message.
- Core processes: Requirements for key generation, the signature process (probabilistic or deterministic) and the verification process.
- Security properties: The standard requires that given only the verification key it is computationally infeasible to forge valid message/signature pairs, recover the private signature key, or find two different messages that share the same signature.
- Hash-function binding: Strong emphasis on binding the chosen hash-function to the signature mechanism to prevent forgery. The document describes options for binding (restricting to a single hash-function, indicating the hash in certificate domain parameters, or specifying the hash in the message) and warns of associated risks.
- Notation and conventions: Defines symbols (H, M, X, Y, Σ, etc.), coding conventions and formats for constructing the appendix and signed message.
- Implementation choices and options: Specifies options for how identification data and optional text fields can be used to convey signer identity or verification key information.
Applications and who uses it
ISO/IEC 14888-1 is aimed at organizations and professionals implementing or evaluating digital signature systems that require the full message for verification:
- Security architects and cryptographic engineers designing PKI-aware applications
- Software developers building signing/verification libraries or secure messaging systems
- PKI operators, certificate authorities and system integrators specifying certificate parameters and hash-policy bindings
- Auditors, compliance officers and security assessors validating that signature mechanisms meet recognized security properties
Practical uses include document signing, code signing, secure email, authentication of transactions, and any application requiring data origin authentication, integrity and non-repudiation using an appendix-style digital signature.
Related standards
- ISO/IEC 14888-2: integer factorization–based mechanisms
- ISO/IEC 14888-3: discrete logarithm–based mechanisms
- ISO/IEC 9796: signature mechanisms giving message recovery
- ISO/IEC 10118: hash-function specifications
Keywords: ISO/IEC 14888-1:2008, digital signatures with appendix, signature mechanism with appendix, hash-function, collision-resistant hash, verification key, signature key, key generation, signature process, verification process, PKI.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 14888-1:2008
Похожие стандарты
Стандарты, упомянутые в описании
BS ISO/IEC 14888-1:2008
ДействующийInformation technology. Security techniques. Digital signatures with appendix. General.
BS ISO/IEC 14888-2:2008
ДействующийInformation technology. Security techniques. Digital signatures with appendix. Integer factorization based me…
BS ISO/IEC 14888-3:2018
ДействующийIT Security techniques. Digital signatures with appendix. Discrete logarithm based mechanisms.
ISO/IEC 9796:1991
ОтменёнInformation technology — Security techniques — Digital signature scheme giving message recovery
ISO/IEC 10118-3:2018
ДействующийIT Security techniques — Hash-functions — Part 3: Dedicated hash-functions
Overview ISO/IEC 10118-3:2018 - IT Security techniques - Hash-functions - Part 3: Dedicated hash‑functions specifies a set of specially designed (dedicated) cryptographic hash‑functions. The standard…