ISO/IEC 9798-2:2019
IT Security techniques — Entity authentication — Part 2: Mechanisms using authenticated encryption
IT Security techniques — Entity authentication — Part 2: Mechanisms using authenticated encryption
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 15
- Дата публикации:
- 3 июня 2019 г.
- Издание:
- ISO/IEC IS 9798 edition 4 version 1
- ICS:
- 35.030
This document specifies entity authentication mechanisms using authenticated encryption algorithms. Four of the mechanisms provide entity authentication between two entities where no trusted third party is involved; two of these are mechanisms to unilaterally authenticate one entity to another, while the other two are mechanisms for mutual authentication of two entities. The remaining mechanisms require an on-line trusted third party for the establishment of a common secret key. They also realize mutual or unilateral entity authentication. Annex A defines Object Identifiers for the mechanisms specified in this document.
Abstract
Overview
ISO/IEC 9798-2:2019 - "IT Security techniques - Entity authentication - Part 2: Mechanisms using authenticated encryption" specifies standardized entity authentication mechanisms that use authenticated encryption algorithms. The standard defines six mechanisms: four that operate without an on-line trusted third party (two for unilateral authentication and two for mutual authentication) and two that require an on-line trusted third party (TTP) to establish common secret keys. Annex A of the standard provides Object Identifiers (OIDs) for the mechanisms.
Key topics and requirements
- Authenticated encryption: Mechanisms rely on authenticated encryption to provide confidentiality, integrity and data origin authentication-ensuring decrypted tokens are unforgeable.
- Mechanism types: Named mechanisms include UNI.TS, UNI.CR (unilateral) and MUT.TS, MUT.CR (mutual), plus TP.TS and TP.CR which involve a TTP.
- Time-variant parameters: Use of random numbers (nonces), time-stamps, or sequence numbers to prevent replay; verification rules depend on the parameter type.
- Secret authentication keys: Claimant and verifier must share a secret key (or share keys with a TTP). Keys must be unique to authentication use, protected, and have appropriate lifetimes to avoid cryptanalysis.
- Token structure & SID constants: Encrypted tokens must include mechanism/instance identifiers (SID) so strings cannot be interchanged or replayed across contexts.
- Unforgeability & integrity: For every key, the authenticated-decryption function must allow detection of forged or manipulated data-only legitimate key holders can create acceptable tokens.
- Protocol pass counts: Number of message passes varies by method - e.g., one-pass possible for some unilateral timestamp methods, two/three passes needed for other challenge–response or mutual cases; TTP involvement adds additional exchanges.
- Operational requirements: If a TTP is used it must be mutually trusted; key management practices (ISO/IEC 11770-1/-2 guidance) are necessary.
Applications and who uses it
- Implementers of secure authentication protocols in enterprise systems, embedded devices, and IoT.
- Security architects and protocol designers selecting authenticated-encryption–based authentication for APIs, network services, and device onboarding.
- Vendors of cryptographic libraries and secure modules that need standards-compliant authentication primitives.
- Organisations requiring interoperable authentication with clear Object Identifiers for mechanism identification and conformance testing.
- Compliance officers and auditors evaluating authentication schemes against international best practices.
Related standards
- ISO/IEC 9798-1 (Entity authentication - General)
- ISO/IEC 19772 (Authenticated encryption guidance)
- ISO/IEC 11770-1, -2 (Key management)
- ISO/IEC 18031 (Random number guidance)
- ISO/IEC 8825-1 (Encoding rules referenced for concatenation)
ISO/IEC 9798-2:2019 is essential when you need standardized, authenticated-encryption–based entity authentication that protects against replay and forgery while supporting both TTP-based and direct shared-key scenarios.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 9798-2:2019
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 9798-1:2010
ДействующийInformation technology — Security techniques — Entity authentication — Part 1: General
Overview - ISO/IEC 9798-1:2010 (Entity authentication - General) ISO/IEC 9798-1:2010 defines the authentication model, terminology, and general requirements for entity authentication mechanisms that…
BS ISO/IEC 19772:2020
ДействующийInformation security. Authenticated encryption.
ISO/IEC 18031:2025
ДействующийInformation technology — Security techniques — Random bit generation
Overview ISO/IEC 18031:2025 - "Information technology - Security techniques - Random bit generation" defines a conceptual model and security requirements for random bit generators (RBGs) used for cry…