ISO/IEC 29192-4:2013
Information technology — Security techniques — Lightweight cryptography — Part 4: Mechanisms using asymmetric techniques
Information technology — Security techniques — Lightweight cryptography — Part 4: Mechanisms using asymmetric techniques
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 26
- Дата публикации:
- 22 мая 2013 г.
- Издание:
- ISO/IEC IS 29192 edition 1 version 1
- ICS:
- 35.030
ISO/IEC 29192-4:2013 specifies three lightweight mechanisms using asymmetric techniques: a) a unilateral authentication mechanism based on discrete logarithms on elliptic curves; b) an authenticated lightweight key exchange (ALIKE) mechanism for unilateral authentication and establishment of a session key; c) an identity-based signature mechanism.
Abstract
Overview
ISO/IEC 29192-4:2013 - Information technology - Security techniques - Lightweight cryptography - Part 4: Mechanisms using asymmetric techniques - specifies three lightweight asymmetric cryptographic mechanisms tailored for constrained environments. The document defines:
- a unilateral authentication mechanism based on discrete logarithms on elliptic curves (often referenced as cryptoGPS);
- an authenticated lightweight key exchange (ALIKE) mechanism for unilateral authentication and session-key establishment (based on a variant of RSA);
- an identity-based signature mechanism that simplifies key management by deriving signer keys from identities.
The standard targets low-resource devices (e.g., RFID tags, sensors, embedded IoT nodes) where computation, memory and power are limited.
Key Topics and Requirements
ISO/IEC 29192-4 defines technical requirements and procedures for each mechanism, including:
- Security requirements for the environment - guidance on assumptions and threat models for constrained deployments.
- Key production - processes for generating and distributing asymmetric pairs, master secret keys (for identity-based schemes), and claimant/signer parameters.
- Authentication exchanges and formats - detailed procedures for unilateral authentication, ALIKE exchanges, and sign/verify operations.
- Session-key derivation - how session keys are derived and handled following ALIKE authenticated exchanges.
- Performance-oriented techniques - support for pre-computation (“coupons”), memory-computation trade-offs (Annex B), and numerical examples (Annex C) to aid implementation in tight-resource contexts.
- Object identifiers and interoperability elements (Annex A) for integration into broader systems.
Normative references include ISO/IEC 15946-1 (elliptic-curve cryptography) and ISO/IEC 29192-1 (lightweight cryptography general).
Practical Applications
ISO/IEC 29192-4 is practical for:
- IoT and RFID device authentication - lightweight unilateral authentication (cryptoGPS) enables identification of constrained provers with minimal runtime cost using offline coupons.
- Secure session establishment - ALIKE provides unilateral authentication plus session-key agreement in environments where full asymmetric protocols are too heavy.
- Simplified signing and verification - identity-based signatures reduce certificate and PKI overhead by deriving signing keys from identities, useful for large fleets of constrained devices.
Typical use-cases: asset tracking, sensor networks, access control, device onboarding, and other low-power embedded systems requiring asymmetric security primitives.
Who Should Use This Standard
- Security architects and engineers designing IoT/RFID systems
- Embedded and firmware developers implementing lightweight cryptography
- Product managers and compliance teams evaluating secure options for constrained devices
- Standards and interoperability bodies aligning device authentication and key-management practices
Related standards and notes
- See ISO/IEC 29192-1 (Lightweight cryptography - General) and ISO/IEC 15946-1 (ECC fundamentals).
- Patent notice: the standard may reference patented techniques; holders identified in the document (e.g., France Telecom, Gemalto, A*STAR/Exploit Technologies) have declared licensing terms. Consult ISO and IEC patent databases for current information.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 29192-4:2013
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS ISO/IEC 15946-1:2016
ДействующийInformation technology. Security techniques. Cryptographic techniques based on elliptic curves. General.
ISO/IEC 29192-1:2012
ДействующийInformation technology — Security techniques — Lightweight cryptography — Part 1: General
Overview ISO/IEC 29192-1:2012 - Information technology - Security techniques - Lightweight cryptography - Part 1: General - defines the foundational terms, requirements and classification rules for l…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…