ISO/IEC 14888-2:2008
Information technology — Security techniques — Digital signatures with appendix — Part 2: Integer factorization based mechanisms
Information technology — Security techniques — Digital signatures with appendix — Part 2: Integer factorization based mechanisms
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 66
- Дата публикации:
- 1 апреля 2008 г.
- Издание:
- ISO/IEC IS 14888 edition 2 version 1
- ICS:
- 35.030
ISO/IEC 14888 specifies digital signature with appendix. As no part of the message is recovered from the signature (the recoverable part of the message is empty), the signed message consists of the signature and the whole message. NOTE ISO/IEC 9796 specifies digital signature giving message recovery. As all or part of the message is recovered from the signature, the recoverable part of the message is not empty. The signed message consists of either the signature only (when the non-recoverable part of the message is empty), or both the signature and the non-recoverable part. ISO/IEC 14888-2:2008 specifies digital signatures with appendix whose security is based on the difficulty of factoring the modulus in use. For each signature scheme, it specifies: the relationships and constraints between all the data elements required for signing and verifying; a signature mechanism, i.e. how to produce a signature of a message with the data elements required for signing; a verification mechanism, i.e. how to verify a signature of a message with the data elements required for verifying. The title of ISO/IEC 14888-2 has changed from Identity-based mechanisms (first edition) to Integer factorization based mechanisms (second edition). ISO/IEC 14888-2:2008 includes the identity-based scheme specified in ISO/IEC 14888-2:1999, namely the GQ1 scheme. This scheme has been revised due to the withdrawal of ISO/IEC 9796:1991 in 1999. Among the certificate-based schemes specified in ISO/IEC 14888-3:1998, it includes all the schemes based on the difficulty of factoring the modulus in use, namely, the RSA, RW and ESIGN schemes. These schemes have been revised due to the withdrawal of ISO/IEC 9796:1991 in 1999. It takes into account ISO/IEC 14888-3:1998/Cor.1:2001, technical corrigendum of the ESIGN scheme. It includes a format mechanism, namely the PSS mechanism, also specified in ISO/IEC 9796-2:2002, and details of how to use it in each of the RSA, RW, GQ1 and ESIGN schemes. It includes new certificate-based schemes that use no format mechanism, namely, the GQ2, GPS1 and GPS2 schemes. For each scheme and its options, as needed, it provides an object identifier.
Abstract
Overview
ISO/IEC 14888-2:2008 defines digital signatures with appendix whose security is based on the difficulty of integer factorization. It is Part 2 of the ISO/IEC 14888 series and specifies the mathematical relationships, signature generation mechanisms, and verification procedures for a family of factorization-based signature schemes. The standard covers both certificate-based and identity-based mechanisms (including RSA, RW, ESIGN, GQ1 and newer GQ2, GPS1, GPS2 schemes) and includes use of the PSS format mechanism where applicable.
Key topics and technical requirements
- Signature model: Digital signatures with appendix - the signature does not recover any part of the message; the signed message = signature + full message.
- Security basis: All schemes depend on the infeasibility of factoring the modulus (n).
- Data element constraints: Specifies required relationships and constraints among domain parameters, private signature keys, and public verification keys.
- Operations defined:
- Key pair generation (requires random bits and prime generation - note: RNG/prime generation methods are out of scope).
- Signature production (deterministic or probabilistic depending on scheme and use of salt).
- Signature verification (deterministic).
- Included schemes:
- Certificate-based: RSA, RW, ESIGN (with corrigendum addressed).
- Identity-based and certificate-based variants: GQ1, GQ2, GPS1, GPS2.
- PSS format mechanism and guidance on using it with RSA, RW, GQ1, ESIGN.
- Auxiliary elements: Object identifiers for schemes/options; annexes with parameter guidance, numerical examples, format mechanisms and interoperability notes.
- Out-of-scope: Random-bit/prime generation techniques and certificate/key management procedures (referenced to ISO/IEC 18031, 18032 and PKI standards).
Applications and intended users
- Implementers building cryptographic libraries and secure applications that require factorization-based digital signatures.
- Security architects and PKI designers selecting signature algorithms (RSA, ESIGN, GN/ GPS schemes) for authentication, non-repudiation and data integrity.
- Compliance officers and auditors verifying conformance to international cryptographic standards.
- Cryptographers and protocol designers referencing standardized mechanisms, PSS formatting, and object identifiers for interoperability.
- Manufacturers of secure signature devices (smart cards, HSMs) ensuring proper parameter constraints and verification behavior.
Related standards
- ISO/IEC 14888-1 (General - digital signatures with appendix)
- ISO/IEC 14888-3 (Discrete logarithm based mechanisms / Part 3)
- ISO/IEC 9796 (signatures with message recovery) - contrasted with appendix-style signatures
- ISO/IEC 10118 (Hash-functions), ISO/IEC 18031/18032 (randomness guidance)
ISO/IEC 14888-2:2008 is essential reading for anyone implementing or specifying factorization-based digital signature systems and seeking standardized, interoperable mechanisms for secure signature generation and verification.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 14888-2:2008
Похожие стандарты
Стандарты, упомянутые в описании
BS ISO/IEC 14888-1:2008
ДействующийInformation technology. Security techniques. Digital signatures with appendix. General.
ISO/IEC 18031:2025
ДействующийInformation technology — Security techniques — Random bit generation
Overview ISO/IEC 18031:2025 - "Information technology - Security techniques - Random bit generation" defines a conceptual model and security requirements for random bit generators (RBGs) used for cry…
BS ISO/IEC 14888-3:2018
ДействующийIT Security techniques. Digital signatures with appendix. Discrete logarithm based mechanisms.
ISO/IEC 9796:1991
ОтменёнInformation technology — Security techniques — Digital signature scheme giving message recovery
ISO/IEC 10118-3:2018
ДействующийIT Security techniques — Hash-functions — Part 3: Dedicated hash-functions
Overview ISO/IEC 10118-3:2018 - IT Security techniques - Hash-functions - Part 3: Dedicated hash‑functions specifies a set of specially designed (dedicated) cryptographic hash‑functions. The standard…