ISO/IEC 9798-1:2010
Information technology — Security techniques — Entity authentication — Part 1: General
Information technology — Security techniques — Entity authentication — Part 1: General
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 11
- Дата публикации:
- 16 июня 2010 г.
- Издание:
- ISO/IEC IS 9798 edition 3 version 1
- ICS:
- 35.030
ISO/IEC 9798-1:2010 specifies an authentication model and general requirements and constraints for entity authentication mechanisms which use security techniques. These mechanisms are used to corroborate that an entity is the one that is claimed. An entity to be authenticated proves its identity by showing its knowledge of a secret. The mechanisms are defined as exchanges of information between entities and, where required, exchanges with a trusted third party. The details of the mechanisms and the contents of the authentication exchanges are given in subsequent parts of ISO/IEC 9798.
Abstract
Overview - ISO/IEC 9798-1:2010 (Entity authentication - General)
ISO/IEC 9798-1:2010 defines the authentication model, terminology, and general requirements for entity authentication mechanisms that use security techniques. It specifies how an entity (the claimant) proves its identity by demonstrating knowledge of a secret, via standardized exchanges (tokens) between entities and, where required, with a trusted third party (TTP). Detailed protocol mechanisms are covered in subsequent parts of ISO/IEC 9798 (Parts 2–6).
Keywords: ISO/IEC 9798-1:2010, entity authentication, security techniques, authentication model, tokens, trusted third party, PKI.
Key topics and technical requirements
- Authentication model and roles
- Defines claimant, verifier, trusted third party, tokens, and message flows.
- Supports unilateral and mutual authentication.
- Exchange structure
- Tokens exchanged between entities; at least one token for unilateral, at least two for mutual authentication.
- Additional passes may be required for challenges or TTP involvement.
- Time-variant parameters
- Use of random numbers, time stamps, and sequence numbers to prevent replay attacks (see Annex B).
- Security properties to consider
- Prevention of replay, reflection, and interleaving attacks; forced-delay concerns.
- Choice of protocol depends on threats and whether a pre-established secret or TTP is available.
- Data composition and uniqueness
- Concatenation of data fields must be unambiguous so constituents can be uniquely resolved (e.g., fixed lengths or canonical encoding).
- Terminology and primitives
- Defines symmetric/asymmetric techniques, cryptographic check functions, public key certificates, tokens, and signature/encryption terminology.
- Scope constraints
- Part 1 specifies requirements and model only; concrete mechanisms and content are in Parts 2–6. Establishment of underlying infrastructure (e.g., PKI) is out of scope.
Practical applications
- Designing and evaluating authentication protocols for:
- Secure network access, client-server authentication, and mutual TLS-style flows.
- Smart cards, IoT device authentication, payment systems, and secure remote services.
- Implementing challenge–response and token-based authentication where robust replay/reflection protections are required.
- Specifying interoperability requirements between systems and vendors for authentication exchanges.
Who should use this standard
- Security architects, protocol designers, system integrators, PKI implementers, product vendors, and compliance auditors working on authentication solutions and secure communications.
Related standards
- ISO/IEC 9798 (Parts 2–6) - concrete mechanisms using symmetric encipherment, digital signatures, cryptographic check functions, zero-knowledge techniques, and manual transfer.
- ISO/IEC 8825-1 referenced for unambiguous encoding (distinguished encoding rules).
This standard is essential when you need a formal, interoperable model and general requirements to design secure entity authentication mechanisms and to reason about threats such as replay and man-in-the-middle attacks.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 9798-1:2010
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO/IEC 9798-2:2008
ОтменёнInformation technology — Security techniques — Entity authentication — Part 2: Mechanisms using symmetric enc…
ISO/IEC 8825-1:2015
ОтменёнInformation technology — ASN.1 encoding rules: Specification of Basic Encoding Rules (BER), Canonical Encodin…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…