ISO/IEC 14888-3:2018
IT Security techniques — Digital signatures with appendix — Part 3: Discrete logarithm based mechanisms
IT Security techniques — Digital signatures with appendix — Part 3: Discrete logarithm based mechanisms
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 155
- Дата публикации:
- 12 ноября 2018 г.
- Издание:
- ISO/IEC IS 14888 edition 4 version 1
- ICS:
- 35.030
This document specifies digital signature mechanisms with appendix whose security is based on the discrete logarithm problem. This document provides — a general description of a digital signature with appendix mechanism, and — a variety of mechanisms that provide digital signatures with appendix. For each mechanism, this document specifies — the process of generating a pair of keys, — the process of producing signatures, and — the process of verifying signatures. Annex A defines object identifiers assigned to the digital signature mechanisms specified in this document, and defines algorithm parameter structures. Annex B defines conversion functions of FE2I, I2FE, FE2BS, BS2I, I2BS, I2OS and OS2I used in this document. Annex D defines how to generate DSA domain parameters.
Abstract
Overview
ISO/IEC 14888-3:2018 - "IT Security techniques - Digital signatures with appendix - Part 3: Discrete logarithm based mechanisms" specifies digital-signature-with-appendix mechanisms whose security relies on the discrete logarithm problem. The standard defines a general model for these mechanisms and gives concrete algorithm specifications. For each mechanism it details key generation, signature production, and signature verification processes. The document also includes annexes that assign object identifiers (OIDs), define conversion functions, and explain DSA domain parameter generation.
Key Topics and Technical Requirements
- General model and processes
- Parameter generation (certificate-based and identity-based approaches)
- Signature process: randomizer, pre-signature, witness/assignment, appendix construction
- Verification process: recomputing pre-signature and witness, witness verification
- Discrete-logarithm-based mechanisms specified
- Classic and elliptic-curve varieties including DSA, KCDSA, SDSA, Pointcheval/Vaudenay, EC-DSA (ECDSA), EC-KCDSA, EC-GDSA, EC-RDSA, EC-SDSA, EC-FSDSA, and SM2
- Identity-based mechanisms (e.g., IBS-1 and related constructions)
- Algorithmic artifacts and structures
- Object identifiers and algorithm parameter structures (Annex A)
- Conversion functions (Annex B) such as FE2I, I2FE, FE2BS, BS2I and OS2I
- Guidance on generating DSA domain parameters (Annex D)
- Security assumptions
- Reliance on hardness of the discrete logarithm problem in appropriate groups (multiplicative groups or elliptic curves)
- Interoperability and conformance
- Clear specification of data formats for keys, signatures and appendices to ensure implementer interoperability
Practical Applications
ISO/IEC 14888-3 is used where digital signatures based on discrete logarithm problems are required:
- Secure email and document signing
- TLS / SSL authentication and certificate issuance (ECDSA/DSA use cases)
- Code signing, firmware updates, and software distribution
- Identity-based security systems and smartcards
- IoT devices and constrained environments using elliptic-curve signatures
- Any application requiring standardized, interoperable digital-signature algorithms and verifiable signature formats
Who should use this standard
- Cryptographers, security architects and protocol designers
- Software engineers implementing signature libraries (DSA, ECDSA, SM2)
- Standards and compliance teams validating conformity and interoperability
- PKI operators and implementers of identity-based signature systems
Related standards
- ISO/IEC 14888-1 (general framework for digital signatures with appendix)
- Standards for hash functions and key management (referenced normative documents within ISO/IEC 14888-3)
- Algorithm-specific national or regional standards (e.g., SM2 technical specs)
Keywords: ISO/IEC 14888-3, digital signatures, discrete logarithm, DSA, ECDSA, SM2, signature verification, key generation, IT security standard.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 14888-3:2018
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS ISO/IEC 14888-3:2018
ДействующийIT Security techniques. Digital signatures with appendix. Discrete logarithm based mechanisms.
BS ISO/IEC 14888-1:2008
ДействующийInformation technology. Security techniques. Digital signatures with appendix. General.
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…