ISO/IEC 9594-8:2020
Information technology — Open systems interconnection — Part 8: The Directory: Public-key and attribute certificate frameworks
Information technology — Open systems interconnection — Part 8: The Directory: Public-key and attribute certificate frameworks
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 224
- Дата публикации:
- 1 декабря 2020 г.
- Издание:
- ISO/IEC IS 9594 edition 9 version 1
- ICS:
- 35.100.70
This document addresses some of the security requirements in the areas of authentication and other security services through the provision of a set of frameworks upon which full services can be based. Specifically, this Recommendation | International Standard defines frameworks for: ? public-key certificates; and ? attribute certificates. The public-key certificate framework defined in this Recommendation | International Standard specifies the information objects and data types for a public-key infrastructure (PKI), including public-key certificates, certificate revocation lists (CRLs), trust broker and authorization and validation lists (AVLs). The attribute certificate framework specifies the information objects and data types for a privilege management infrastructure (PMI), including attribute certificates, and attribute certificate revocation lists (ACRLs). This Recommendation | International Standard also provides the framework for issuing, managing, using and revoking certificates. An extensibility mechanism is included in the defined formats for both certificate types and for all revocation list schemes. This Recommendation | International Standard also includes a set of extensions, which is expected to be generally useful across a number of applications of PKI and PMI. The schema components (including object classes, attribute types and matching rules) for storing PKI and PMI information in a directory, are included in this Recommendation | International Standard. This Recommendation | International Standard specifies the framework for strong authentication, involving credentials formed using cryptographic techniques. It is not intended to establish this as a general framework for authentication, but it can be of general use for applications which consider these techniques adequate. Authentication (and other security services) can only be provided within the context of a defined security policy. It is a matter for users of an application to define their own security policy.
Abstract
Overview
ISO/IEC 9594-8:2020 - also published as ITU‑T X.509 (10/2019) - defines the public-key and attribute certificate frameworks used in Directory services. This international standard specifies the information objects, data types and schema components required for a public‑key infrastructure (PKI) and a privilege management infrastructure (PMI). It covers certificate formats, revocation mechanisms (CRLs and ACRLs), authorization and validation lists (AVLs), extensibility for certificate and revocation schemes, and directory schema elements (object classes, attribute types and matching rules) for storing PKI/PMI data.
Key Topics and Requirements
- Public‑key certificate framework (PKI):
- Defines public‑key certificates, certificate revocation lists (CRLs), trust anchors, and certification path concepts.
- Specifies certificate creation, key‑pair generation guidance, and certificate/CRL extension mechanisms.
- Attribute certificate framework (PMI):
- Defines attribute certificates, attribute certificate revocation lists (ACRLs), delegation paths and privilege representations for access control.
- Revocation and validation:
- Standardizes CRL/ACRL formats, delta CRLs, indirect CRLs and Authorization and Validation Lists (AVLs) to support certificate status checking.
- Directory schema and encoding:
- Provides ASN.1‑based schema components for storing PKI/PMI data in a Directory (object classes, attribute types, matching rules).
- Prescribes Distinguished Encoding Rules (DER) use for canonical representations.
- Extensions & extensibility:
- Includes a set of generally useful certificate and revocation extensions and specifies mechanisms to extend formats safely.
- Security scope:
- Specifies strong authentication frameworks based on cryptographic credentials; emphasizes that authentication and other services must be applied within a defined security policy.
Applications and Practical Uses
- Implementing and operating Certificate Authorities (CAs) and Attribute Authorities for enterprise and public PKI/PMI.
- Designing directory services that store certificates, revocation data and authorization metadata.
- Enabling secure protocols and services that rely on X.509 certificates: TLS/SSL, secure email (S/MIME), code signing, enterprise single sign‑on, device identity for IoT, smart cards and access control systems.
- Building certificate validation and revocation checking mechanisms in client and server software.
- Guiding policy authors, security architects and auditors on certificate, revocation and directory data models.
Who Should Use This Standard
- PKI/PMI implementers, CA operators and directory administrators
- Security architects, identity and access management (IAM) engineers
- Software vendors building TLS/PKI clients, OCSP/CRL processors and directory servers
- Regulators and auditors evaluating certificate management practices
Related Standards
- ITU‑T X.509 (10/2019) - source specification aligned with this edition
- Other parts of the ISO/IEC 9594 series (The Directory) for complementary Directory protocols and models
Keywords: ISO/IEC 9594-8:2020, X.509, public-key certificate, attribute certificate, PKI, PMI, CRL, ACRL, directory schema, certificate revocation, strong authentication, ASN.1, DER.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 6 - Telecommunications and information exchange between systems
- SKU
- ISO/IEC 9594-8:2020
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO/IEC 9594-2:2020
ДействующийInformation technology — Open systems interconnection — Part 2: The Directory: Models
Overview ISO/IEC 9594-2:2020 (ITU‑T X.501) defines the conceptual and terminological framework for the X.500-series Directory family. It specifies the Directory information models, Directory System A…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…