ISO/IEC 29192-7:2019
Information security — Lightweight cryptography — Part 7: Broadcast authentication protocols
Information security — Lightweight cryptography — Part 7: Broadcast authentication protocols
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 7
- Дата публикации:
- 16 июля 2019 г.
- Издание:
- ISO/IEC IS 29192 edition 1 version 1
- ICS:
- 35.030
This document specifies broadcast authentication protocols, which are protocols that provide data integrity and entity authentication in a broadcast setting, i.e. a setting with one sender transmitting messages to many receivers. To provide entity authentication, there needs to be a pre-existing infrastructure which links the sender to a cryptographic secret. The establishment of such an infrastructure is beyond the scope of this document.
Abstract
Overview
ISO/IEC 29192-7:2019 - "Information security - Lightweight cryptography - Part 7: Broadcast authentication protocols" defines lightweight broadcast authentication protocols for constrained environments. The standard focuses on providing data integrity and entity authentication in one-to-many (broadcast) settings where digital signatures may be too costly. It specifies protocol structure, system parameters and a concrete lightweight option (TESLA‑RD), while leaving the establishment of the key‑binding infrastructure (linking a sender to a cryptographic secret) out of scope.
Key topics and requirements
- TESLA‑RD (Timed Efficient Stream Loss‑tolerant Authentication - Rapid Disclosure): the primary protocol described for lightweight broadcast authentication.
- Cryptographic primitives:
- MAC algorithms from ISO/IEC 9797 or ISO/IEC 29192‑6.
- Collision‑resistant hash functions from ISO/IEC 10118 or ISO/IEC 29192‑5.
- Chain of keys: keys are generated by repeatedly applying a collision‑resistant hash to a random seed key (K_N) and optional value α to resist time‑memory trade‑off attacks.
- Time‑based operation:
- Time is split into fixed intervals (parameter D).
- A disclosure delay (d) defines how long after sending a MAC the key used to compute it is revealed.
- The receiver’s and sender’s clocks must be synchronized within a known bound (ε).
- Operational phases: Initialization, Setup (key chain generation and distribution), Sending messages (MAC + interval index + disclosed key), Receiving/storing packets, Verifying keys via hash chains, and Verifying message MACs.
- System parameters: D, d, N (chain length), α length and representation details are public and decided before deployment.
- Object identifiers: Annex A assigns OIDs for algorithms used in the document.
Practical applications
- Broadcast scenarios where low overhead is critical:
- Satellite telemetry and satellite broadcast services
- Wireless sensor networks and IoT/mass‑deployed devices
- Firmware/firmware update distribution over broadcast links
- Digital radio, telemetry streams, and other multicast systems
- Environments with constrained CPU, memory and communication budgets where digital signatures are impractical.
Who should use this standard
- Security architects and systems engineers designing broadcast or multicast authentication for constrained devices.
- Embedded and IoT developers implementing lightweight cryptographic protocols.
- Satellite communications and telemetry engineers seeking low‑cost authentication mechanisms.
- Standards compliance teams and evaluators verifying conformance with lightweight broadcast authentication practice.
Related standards
- ISO/IEC 29192 series (Lightweight cryptography - general, hash‑functions, MACs)
- ISO/IEC 9797 (Message authentication codes)
- ISO/IEC 10118 (Hash‑functions)
Keywords: ISO/IEC 29192-7:2019, lightweight cryptography, broadcast authentication, TESLA‑RD, MAC, hash function, chain of keys, IoT security, satellite telemetry.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 29192-7:2019
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 9797-3:2011
ДействующийInformation technology — Security techniques — Message Authentication Codes (MACs) — Part 3: Mechanisms using…
Overview ISO/IEC 9797-3:2011 - "Information technology - Security techniques - Message Authentication Codes (MACs) - Part 3: Mechanisms using a universal hash-function" - specifies MAC algorithms tha…
BS ISO/IEC 29192-6:2019
ДействующийInformation technology. Lightweight cryptography. Message authentication codes (MACs).
ISO/IEC 10118-3:2018
ДействующийIT Security techniques — Hash-functions — Part 3: Dedicated hash-functions
Overview ISO/IEC 10118-3:2018 - IT Security techniques - Hash-functions - Part 3: Dedicated hash‑functions specifies a set of specially designed (dedicated) cryptographic hash‑functions. The standard…