ISO/IEC 18033-2:2006
Information technology — Security techniques — Encryption algorithms — Part 2: Asymmetric ciphers
Information technology — Security techniques — Encryption algorithms — Part 2: Asymmetric ciphers
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 125
- Дата публикации:
- 8 мая 2006 г.
- Издание:
- ISO/IEC IS 18033 edition 1 version 1
- ICS:
- 35.030
ISO/IEC 18033-2:2006 specifies encryption systems (ciphers) for the purpose of data confidentiality. The primary purpose of encryption (or encipherment) techniques is to protect the confidentiality of stored or transmitted data. An encryption algorithm is applied to data (often called plaintext or cleartext) to yield encrypted data (or ciphertext); this process is known as encryption. The encryption algorithm should be designed so that the ciphertext yields no information about the plaintext except, perhaps, its length. Associated with every encryption algorithm is a corresponding decryption algorithm, which transforms ciphertext back into its original plaintext. An asymmetric, i.e. public-key, encryption scheme allows a sender to use a recipient's public key to transmit an encryption of a message to the receiver, who can use his secret key to decrypt the given ciphertext, thereby obtaining the original message. Such a scheme should be secure in the sense that no information about the message should be leaked to a (resource-bounded) attacker, even if that attacker mounts a so-called 'chosen ciphertext' attack, in which he may obtain decryptions of other ciphertexts. This is the strongest type of attack that has been proposed for a public-key encryption scheme. ISO/IEC 18033-2:2006 specifies the functional interface of such a scheme, and in addition specifies a number of particular schemes that appear to be secure against chosen ciphertext attack. The different schemes offer different trade-offs between security properties and efficiency.
Abstract
Overview
ISO/IEC 18033-2:2006 - Information technology - Security techniques - Encryption algorithms - Part 2: Asymmetric ciphers - specifies functional interfaces, correct usage, and ciphertext formats for a set of asymmetric (public‑key) encryption schemes. The standard focuses on protecting the confidentiality of stored and transmitted data by defining how public-key encryption and hybrid schemes (combining asymmetric and symmetric techniques) should operate. It also includes normative ASN.1 syntax for object identifiers and key/parameter structures.
Key topics and technical requirements
- Asymmetric ciphers and interfaces: Defines the functional interface for public‑key encryption and associated decryption operations.
- Security model: Emphasises resistance to strong adversaries, including chosen ciphertext attacks (CCA), the strongest attack model for public‑key schemes.
- Specified schemes: Includes concrete constructions and trade‑offs for widely used approaches such as:
- ElGamal‑based hybrid ciphers (e.g., ECIES‑HC, PSEC‑HC, ACE‑HC)
- RSA‑based ciphers and KEMs (including RSAES - OAEP applied to RSA - and RSA‑KEM)
- Ciphers based on modular squaring (e.g., HIME(R))
- Hybrid constructions: Formalizes Key Encapsulation Mechanisms (KEMs) and Data Encapsulation Mechanisms (DEMs) and how to combine them into generic hybrid ciphers, covering DEM variants and HC operation.
- Supporting primitives and formats: Describes use of hash functions, key derivation functions, MACs, block/symmetric ciphers, finite fields and elliptic curves; includes ASN.1 syntax (Annex A), security considerations (Annex B) and test vectors (Annex C).
- Normative references & limits: Refers to related standards for MACs, hash functions and block ciphers; does not prescribe key distribution or proof‑of‑possession protocols-see ISO/IEC 11770‑3 for key management guidance.
Applications and who uses it
- Cryptographic library implementers - to implement interoperable asymmetric encryption, KEM/DEM and hybrid schemes consistent with international formats.
- Security architects and system designers - to select appropriate public‑key encryption constructions and understand trade‑offs between security (CCA resistance) and performance.
- Product vendors and integrators - for implementing secure data confidentiality features in messaging, storage, TLS-like systems, and key transport.
- Standards bodies and auditors - for conformance testing and referencing ASN.1 object identifiers and test vectors.
Related standards (selection)
- ISO/IEC 18033‑1 (General)
- ISO/IEC 18033‑3 (Block ciphers)
- ISO/IEC 11770‑3 (Key management guidance)
- ISO/IEC 9797‑1 / 9797‑2, ISO/IEC 10118‑2 / 10118‑3 (MACs and hash functions)
Keywords: ISO/IEC 18033-2:2006, asymmetric ciphers, public-key encryption, hybrid cipher, KEM, DEM, ECIES, RSAES, chosen ciphertext attack, data confidentiality.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 18033-2:2006
Похожие стандарты
Стандарты, упомянутые в описании
BS ISO/IEC 11770-3:2021
ДействующийInformation security. Key management. Mechanisms using asymmetric techniques.
BS ISO/IEC 18033-1:2021
ДействующийInformation security. Encryption algorithms. General.
ISO/IEC 18033-3:2010
ДействующийInformation technology — Security techniques — Encryption algorithms — Part 3: Block ciphers
Overview ISO/IEC 18033-3:2010 - "Information technology - Security techniques - Encryption algorithms - Part 3: Block ciphers" is the international standard that specifies a set of block cipher algor…
ISO/IEC 9797-1:2011
ДействующийInformation technology — Security techniques — Message Authentication Codes (MACs) — Part 1: Mechanisms using…
Overview ISO/IEC 9797-1:2011 - Information technology - Security techniques - Message Authentication Codes (MACs) - Part 1: Mechanisms using a block cipher specifies six standardized MAC algorithms t…