ISO/IEC 9796-3:2006
Information technology — Security techniques — Digital signature schemes giving message recovery — Part 3: Discrete logarithm based mechanisms
Information technology — Security techniques — Digital signature schemes giving message recovery — Part 3: Discrete logarithm based mechanisms
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 69
- Дата публикации:
- 12 сентября 2006 г.
- Издание:
- ISO/IEC IS 9796 edition 2 version 1
- ICS:
- 35.030
A digital signature in electronic exchange of information provides the same kind of facilities that are expected from a handwritten signature in paper-based mail. Hence it is applicable to providing entity authentication, data origin authentication, non-repudiation, and integrity of data. ISO/IEC 9796-3:2006 specifies digital signature mechanisms giving partial or total message recovery aiming at reducing storage and transmission overhead. ISO/IEC 9796-3:2006 specifies mechanisms based on the discrete logarithm problem of a finite field or an elliptic curve over a finite field. ISO/IEC 9796-3:2006 defines types of redundancy: natural redundancy, added redundancy, or both. ISO/IEC 9796-3:2006 gives the general model for digital signatures giving partial or total message recovery aiming at reducing storage and transmission overhead. ISO/IEC 9796-3:2006 specifies six digital signature schemes giving data recovery: NR, ECNR, ECMR, ECAO, ECPV, and ECKNR. NR is defined on a prime field; ECNR, ECMR, ECAO, ECPV, and ECKNR are defined on an elliptic curve over a finite field.
Abstract
Overview
ISO/IEC 9796-3:2006 defines digital signature schemes giving message recovery based on the discrete logarithm problem. The standard specifies randomized signature mechanisms that enable partial or total message recovery from the signature itself, reducing storage and transmission overhead compared with signature-with-appendix approaches. Schemes are defined on a prime field or on elliptic curves over finite fields, and support services such as entity authentication, data origin authentication, non‑repudiation, and integrity.
Key topics and requirements
- Scope: Digital signatures that allow recovery of all or part of the signed message to save bandwidth and storage.
- Mechanisms: Six discrete-logarithm‑based schemes are specified: NR (Nyberg–Rueppel), ECNR, ECMR, ECAO, ECPV, and ECKNR. NR uses a prime field; the others are elliptic‑curve based.
- Core processes: formal models for parameter generation, user key generation, signature generation, and signature verification are defined.
- Redundancy models: support for natural redundancy, added redundancy, or a combination to enable reliable message recovery and integrity checking.
- Hash and mask binding: specification of how signature mechanisms bind to hash functions and allowable mask generation (key‑derivation) functions (e.g., MGF variants).
- Data and conversion functions: conversions between bit/ octet strings, finite‑field elements and elliptic‑curve points, plus an ASN.1 module for representation and interchange.
- Security properties: requirements that signatures resist forgery, key recovery, and second‑preimage issues under standard cryptographic assumptions.
- Implementation guidance: informative annexes with mathematical conventions, conversion and mask functions, example data construction, numeric examples, and a summary of mechanism properties.
- Patents: the standard notes claimed patent interests for NR, ECMR and ECAO; implementers should review patent/licensing terms.
Applications and who should use it
ISO/IEC 9796-3 is useful for:
- Cryptographic library developers implementing digital-signature APIs that support message recovery.
- Security architects designing low-bandwidth or constrained systems (smart cards, IoT, embedded devices) where reducing message transmission or storage matters.
- Electronic document and secure email systems that need non‑repudiation while optimizing payload size.
- Standards and compliance teams assessing interoperable signature formats for protocols using elliptic‑curve or discrete‑logarithm cryptography.
Practical application areas include secure firmware signing, e‑transaction receipts, constrained-network communications, and smart‑card authentication systems.
Related standards
- ISO/IEC 9796‑2 - integer factorization based mechanisms (complementary family)
- ISO/IEC 15946‑1 - elliptic curve cryptography background and techniques
- ISO/IEC 10118 - hash function standards
- ISO/IEC 14888 - signature framework and terminology
Keywords: ISO/IEC 9796-3, digital signature schemes, message recovery, elliptic curve, discrete logarithm, NR, ECNR, ECMR, ECAO, ECPV, ECKNR, non-repudiation, entity authentication.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 9796-3:2006
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 9796-2:2010
ДействующийInformation technology — Security techniques — Digital signature schemes giving message recovery — Part 2: In…
Overview ISO/IEC 9796-2:2010 - "Information technology - Security techniques - Digital signature schemes giving message recovery - Part 2: Integer factorization based mechanisms" specifies three digi…
BS ISO/IEC 15946-1:2016
ДействующийInformation technology. Security techniques. Cryptographic techniques based on elliptic curves. General.
ISO/IEC 10118-3:2018
ДействующийIT Security techniques — Hash-functions — Part 3: Dedicated hash-functions
Overview ISO/IEC 10118-3:2018 - IT Security techniques - Hash-functions - Part 3: Dedicated hash‑functions specifies a set of specially designed (dedicated) cryptographic hash‑functions. The standard…