ISO/IEC 9594-11:2025
Information technology — Open systems interconnection directory — Part 11: Protocol specifications for secure operations
Information technology — Open systems interconnection directory — Part 11: Protocol specifications for secure operations
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 120
- Дата публикации:
- 27 августа 2025 г.
- Издание:
- ISO/IEC IS 9594 edition 2 version 1
- ICS:
- 35.100.70
This document provides guidance on how to prepare new and old protocols for cryptographic algorithm migration and defines auxiliary cryptographic algorithms to be used for migration purposes. This document specifies a general wrapper protocol that provides authentication, integrity and confidentiality (encryption) protection for other protocols. This wrapper protocol includes a migration path for cryptographic algorithms allowing for smooth migration to stronger cryptographic algorithms as such requirements evolve. This will allow migration to quantum-safe cryptographic algorithms. Protected protocols can then be developed without taking security and cryptographic algorithms into consideration. This document also includes some protocols to be protected by the wrapper protocol primarily for support of public-key infrastructure (PKI). Other specifications, e.g., Recommendations or International Standards, may also develop protocols designed to be protected by the wrapper protocol.
Abstract
Overview - ISO/IEC 9594-11:2025 (Directory - Protocol specifications for secure operations)
ISO/IEC 9594-11:2025 defines a standardized approach to securing Open Systems Interconnection (OSI) directory protocols by specifying a general wrapper protocol that provides authentication, integrity and confidentiality for other protocols. The standard focuses on enabling smooth cryptographic algorithm migration (including migration to quantum‑safe algorithms) so protected protocols can be developed without embedding specific cryptographic algorithms. This second edition (prepared as ITU‑T X.510) replaces the 2020 edition and updates protocol, cryptographic and key‑management guidance for directory services and PKI-related operations.
Key technical topics and requirements
-
Wrapper protocol architecture
- General concepts, communication model, data unit structure and error handling for the wrapper that encapsulates protected protocols.
- Association (handshake), data transfer and release procedures; sequence numbers; invocation identifiers.
-
Cryptographic algorithm migration
- Guidance and auxiliary algorithm specifications to support migration paths and coexistence of old and new algorithms.
- Mechanisms to allow switching to stronger / quantum‑safe algorithms without redesigning protected protocols.
-
Cryptographic primitives and key management
- Specification of symmetric algorithms (e.g., AES, Camellia, SEED, SM4).
- Public‑key and digital signature algorithm coverage and key establishment methods including Diffie‑Hellman (prime field) and Elliptic Curve Diffie‑Hellman (ECDH).
- Key derivation, symmetric key renewal and sequence number usage.
-
Protected protocols (examples)
- Protocols for Public Key Infrastructure (PKI) support such as certification authority subscription and authorization/validation list management.
- Plug‑in model for other standards to be secured by the wrapper protocol.
-
Data types, ASN.1 tooling and multiple‑algorithm specification
- Use of ASN.1 information object class tools and parameterized data types to express multi‑algorithm values and algorithm identifiers.
Practical applications and who uses this standard
- Directory service implementers and vendors securing LDAP/OSI directory interactions.
- PKI operators and Certification Authorities implementing subscription, certificate distribution and validation management.
- Security architects designing protocol stacks that must remain algorithm‑agile and future‑proof against quantum threats.
- Product teams building secure middleware, gateways or appliances that need a standard wrapper to protect diverse application protocols.
- Standards bodies and specification authors who want their protocols to be interoperable with a standardized, algorithm‑migratable security layer.
Related standards and references
- ISO/IEC 9594 series (Directory standards)
- ITU‑T Recommendation X.510 (basis for this edition)
- Relevant cryptographic algorithm standards (e.g., AES) and future quantum‑safe algorithm specifications
Keywords: ISO/IEC 9594-11:2025, wrapper protocol, cryptographic algorithm migration, quantum‑safe, directory, PKI, ASN.1, Diffie‑Hellman, AES, secure operations.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 6 - Telecommunications and information exchange between systems
- SKU
- ISO/IEC 9594-11:2025
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO/IEC 9594-2:2020
ДействующийInformation technology — Open systems interconnection — Part 2: The Directory: Models
Overview ISO/IEC 9594-2:2020 (ITU‑T X.501) defines the conceptual and terminological framework for the X.500-series Directory family. It specifies the Directory information models, Directory System A…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…