ISO/IEC 15946-5:2022
Information security — Cryptographic techniques based on elliptic curves — Part 5: Elliptic curve generation
Information security — Cryptographic techniques based on elliptic curves — Part 5: Elliptic curve generation
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 35
- Дата публикации:
- 28 февраля 2022 г.
- Издание:
- ISO/IEC IS 15946 edition 3 version 1
- ICS:
- 35.030
The ISO/IEC 15946 series specifies public-key cryptographic techniques based on elliptic curves described in ISO/IEC 15946-1. This document defines elliptic curve generation techniques useful for implementing the elliptic curve based mechanisms defined in ISO/IEC 29192‑4, ISO/IEC 9796‑3, ISO/IEC 11770‑3, ISO/IEC 14888‑3, ISO/IEC 18033‑2 and ISO/IEC 18033‑5. This document is applicable to cryptographic techniques based on elliptic curves defined over finite fields of prime power order (including the special cases of prime order and characteristic two). This document is not applicable to the representation of elements of the underlying finite field (i.e. which basis is used).
Abstract
Overview
ISO/IEC 15946-5:2022 - "Information security - Cryptographic techniques based on elliptic curves - Part 5: Elliptic curve generation" defines standard methods for generating elliptic curves suitable for secure cryptographic use. It is the third edition (2022) of this part of the ISO/IEC 15946 series and focuses on generation techniques for elliptic curve cryptography (ECC) over finite fields of prime power order (including prime order and characteristic two). The document does not prescribe how finite field elements are represented (choice of basis).
Key topics and technical requirements
- Framework and conventions: definitions, symbols, conversion functions, and group law conventions for elliptic curves over F(p), F(2^m) and F(3^m).
- Verifiably pseudo-random curve generation:
- Algorithms for constructing verifiably pseudo-random curves in the prime and binary field cases.
- Tests and procedures: near-primality testing, finding points of large prime order, and verification of pseudo-randomness.
- Complex multiplication (CM) method:
- Prescribed CM techniques for constructing curves including treatment of pairing‑friendly curves.
- Specific examples and guidance for Barreto–Naehrig (BN) and Barreto–Lynn‑Scott (BLS) families.
- Lifting methods: techniques for constructing curves by lifting from smaller fields.
- Security considerations and examples:
- Annexes provide background on ECC, pairing security (including recent concerns such as exTNFS for some BN curve parameters), numerical examples and property summaries.
- Interoperability rules: guidance to ensure generated curves are suitable for use in standardized cryptographic mechanisms.
Applications
ISO/IEC 15946-5:2022 is intended to support secure key management, digital signatures, public-key encryption, and pairing-based protocols. It supplies curve generation techniques usable by implementations of other standards such as:
- ISO/IEC 29192‑4 (lightweight cryptography - ECC)
- ISO/IEC 9796‑3 (signature schemes)
- ISO/IEC 11770‑3 (key management)
- ISO/IEC 14888‑3 (digital signatures)
- ISO/IEC 18033‑2 and 18033‑5 (encryption)
Practical uses include:
- Generating standardized, verifiable ECC domain parameters for cryptographic libraries
- Selecting or creating pairing-friendly curves (BN, BLS) with documented security properties
- Producing curves for constrained devices and lightweight cryptography where parameter size matters
Who should use this standard
- Cryptographic engineers and protocol designers
- Security architects and system integrators
- Cryptographic library and hardware token implementers
- Standards bodies and auditors evaluating curve generation and parameter provenance
Related standards
- ISO/IEC 15946-1 (General)
- ISO/IEC 29192‑4, 9796‑3, 11770‑3, 14888‑3, 18033‑2, 18033‑5 (as listed in the scope)
Keywords: elliptic curve generation, ECC, elliptic curve cryptography, verifiably pseudo-random curves, complex multiplication, BN curves, BLS curves, finite fields, ISO/IEC 15946-5.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 15946-5:2022
Похожие стандарты
Стандарты, упомянутые в описании
BS ISO/IEC 15946-5:2022
ДействующийInformation security. Cryptographic techniques based on elliptic curves. Elliptic curve generation.
ISO/IEC 29192-4:2013
ДействующийInformation technology — Security techniques — Lightweight cryptography — Part 4: Mechanisms using asymmetric…
Overview ISO/IEC 29192-4:2013 - Information technology - Security techniques - Lightweight cryptography - Part 4: Mechanisms using asymmetric techniques - specifies three lightweight asymmetric crypt…
ISO/IEC 9796-3:2006
ДействующийInformation technology — Security techniques — Digital signature schemes giving message recovery — Part 3: Di…
Overview ISO/IEC 9796-3:2006 defines digital signature schemes giving message recovery based on the discrete logarithm problem. The standard specifies randomized signature mechanisms that enable part…
BS ISO/IEC 11770-3:2021
ДействующийInformation security. Key management. Mechanisms using asymmetric techniques.
BS ISO/IEC 14888-3:2018
ДействующийIT Security techniques. Digital signatures with appendix. Discrete logarithm based mechanisms.
ISO/IEC 18033-2:2006
ДействующийInformation technology — Security techniques — Encryption algorithms — Part 2: Asymmetric ciphers
Overview ISO/IEC 18033-2:2006 - Information technology - Security techniques - Encryption algorithms - Part 2: Asymmetric ciphers - specifies functional interfaces, correct usage, and ciphertext form…