ISO/IEC 18367:2016
Information technology — Security techniques — Cryptographic algorithms and security mechanisms conformance testing
Information technology — Security techniques — Cryptographic algorithms and security mechanisms conformance testing
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 68
- Дата публикации:
- 8 декабря 2016 г.
- Издание:
- ISO/IEC IS 18367 edition 1 version 1
- ICS:
- 35.030
ISO/IEC 18367:2016 gives guidelines for cryptographic algorithms and security mechanisms conformance testing methods. Conformance testing assures that an implementation of a cryptographic algorithm or security mechanism is correct whether implemented in hardware, software or firmware. It also confirms that it runs correctly in a specific operating environment. Testing can consist of known-answer or Monte Carlo testing, or a combination of test methods. Testing can be performed on the actual implementation or modelled in a simulation environment. ISO/IEC 18367:2016 does not include the efficiency of the algorithms or security mechanisms nor the intrinsic performance. This document focuses on the correctness of the implementation.
Abstract
Overview
ISO/IEC 18367:2016 - Information technology - Security techniques - Cryptographic algorithms and security mechanisms conformance testing - provides authoritative guidelines for verifying the correctness of cryptographic algorithm and security mechanism implementations. The standard covers testing whether an implementation (hardware, software or firmware) performs the algorithm or mechanism correctly in a given operating environment. It explicitly focuses on functional conformance and does not address algorithm efficiency or intrinsic performance.
Keywords: ISO/IEC 18367:2016, cryptographic algorithms, conformance testing, security mechanisms, correctness testing
Key topics
- Types of algorithms and mechanisms addressed: symmetric key (block/stream ciphers), asymmetric key (RSA, DSA, ECDSA), digital signatures (including message recovery), hashing, message authentication codes (MAC), random bit generators (DRBG and non-deterministic), key establishment, key derivation functions (KDF), prime number generation, authenticated encryption, and lightweight cryptography.
- Testing methodologies: black-box (known-answer tests, multi-block tests, Monte Carlo/statistical tests), white-box/glass-box (source code inspection, binary analysis), and simulation-based testing alternatives.
- Levels of conformance: defined tiers (basic, moderate, etc.) to scale test depth depending on risk and assurance requirements.
- Test design guidance: identification of algorithm instances, selection of test items, and detailed guidelines for each algorithm class (e.g., hashing, MAC, KDF, DRBG).
- Practical test types: known-answer test vectors, Monte Carlo statistical tests, multi-block messaging, and examples of typical implementation mistakes (informative annexes).
Keywords: black box testing, white box testing, known-answer tests, Monte Carlo testing, DRBG, KDF, hashing, MAC
Applications
- Validate that a cryptographic implementation correctly implements the intended algorithms in its real operating environment.
- Support laboratory test plans for conformance verification, QA, code review and binary analysis.
- Provide guidance for interoperability testing between products that implement standardized cryptographic primitives.
- Form a baseline for security evaluators and product teams to design meaningful test suites that focus on correctness rather than performance.
Keywords: conformance verification, cryptographic testing, interoperability testing, QA
Who uses this standard
- Cryptographic implementers (software, firmware, hardware)
- Test laboratories and independent security evaluators
- QA and engineering teams building secure systems
- Certification and compliance bodies designing test programs
- Product architects ensuring interoperable cryptographic behavior
Related standards
- ISO/IEC 18031 (deterministic random bit generation) is referenced in ISO/IEC 18367:2016 for DRBG testing guidance.
- ISO/IEC 18367 is complementary to other ISO/IEC standards that address cryptographic modules, testing frameworks and security requirements.
Using ISO/IEC 18367:2016 helps organizations create repeatable, standards-based conformance tests that improve trust in cryptographic implementations without conflating correctness with performance metrics.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 18367:2016
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO/IEC 18031:2025
ДействующийInformation technology — Security techniques — Random bit generation
Overview ISO/IEC 18031:2025 - "Information technology - Security techniques - Random bit generation" defines a conceptual model and security requirements for random bit generators (RBGs) used for cry…
BS ISO/IEC 18367:2016
ДействующийInformation technology. Security techniques. Cryptographic algorithms and security mechanisms conformance tes…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…