ISO/IEC 9798-5:2009
Information technology — Security techniques — Entity authentication — Part 5: Mechanisms using zero-knowledge techniques
Information technology — Security techniques — Entity authentication — Part 5: Mechanisms using zero-knowledge techniques
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 53
- Дата публикации:
- 11 декабря 2009 г.
- Издание:
- ISO/IEC IS 9798 edition 3 version 1
- ICS:
- 35.030
ISO/IEC 9798-5:2009 specifies entity authentication mechanisms using zero-knowledge techniques: mechanisms based on identities and providing unilateral authentication; mechanisms based on integer factorization and providing unilateral authentication; mechanisms based on discrete logarithms with respect to numbers that are either prime or composite, and providing unilateral authentication; mechanisms based on asymmetric encryption systems and providing either unilateral authentication, or mutual authentication; mechanisms based on discrete logarithms on elliptic curves and providing unilateral authentication. These mechanisms are constructed using the principles of zero-knowledge techniques, but they are not necessarily zero-knowledge according to the strict definition for every choice of parameters.
Abstract
Overview
ISO/IEC 9798-5:2009 - part of the ISO/IEC 9798 series - specifies entity authentication mechanisms using zero-knowledge techniques. Published as the third edition in 2009, it defines a family of authentication exchanges between a claimant and a verifier built on zero-knowledge principles. The standard covers mechanisms based on identities, integer factorization, discrete logarithms (prime and composite moduli), asymmetric encryption systems (supporting unilateral or mutual authentication), and elliptic-curve discrete logarithms. It also provides normative and informative annexes with object identifiers, zero-knowledge principles, parameter guidance, and numerical examples.
Key topics and technical requirements
- Mechanism families: identity-based, integer-factorization-based, discrete-logarithm-based (prime/composite), asymmetric-encryption-based (unilateral/mutual), and elliptic-curve discrete logarithm mechanisms.
- Authentication flows: definitions and formats for witness, challenge, response, and the exchange multiplicity of messages in an authentication instance.
- Key production and management: procedures and requirements for generating private/public keys, accreditation exponents, adaptation parameters, and domain parameters.
- Security environment requirements: prerequisites for safe deployment of each mechanism family (e.g., randomness, parameter selection, and computational assumptions).
- Operational concepts: unilateral vs mutual authentication, coupon strategy (pre-computation to reduce runtime work for constrained claimants or verifiers), and token/claimant parameter handling.
- Parameter guidance: Annex C provides guidance on choosing parameters and comparing mechanisms; Annex D includes numerical examples to aid implementation.
- Terminology: clear definitions of claimant, verifier, private/public key, secret/response, token, and other cryptographic terms used in entity authentication.
- Caveat: mechanisms follow zero-knowledge principles but “may not be strictly zero-knowledge” for every parameter choice - implementers must heed parameter guidance.
Applications and who uses it
ISO/IEC 9798-5 is targeted at professionals designing and implementing strong authentication for systems that require cryptographic assurance of identity:
- Security architects and protocol designers building authentication schemes
- PKI and certificate authorities integrating authentication primitives
- Cryptographers and researchers comparing zero-knowledge-based schemes
- Embedded and IoT device manufacturers using coupon strategies to offload compute
- Auditors, compliance teams and vendors assessing cryptographic authentication mechanisms
Practical uses include secure login, device pairing, firmware/authentication tokens, challenge–response APIs, and protocols where private keys must be proven without disclosure.
Related standards
- ISO/IEC 9798 (other parts): Part 1 (General), Part 2 (symmetric algorithms), Part 3 (digital signatures), Part 4 (cryptographic check function), Part 6 (manual data transfer).
- Annexes in ISO/IEC 9798-5: principles of zero-knowledge (B), parameter guidance (C), numerical examples (D).
Keywords: ISO/IEC 9798-5:2009, entity authentication, zero-knowledge techniques, discrete logarithm, elliptic curve, integer factorization, asymmetric encryption, authentication mechanisms.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 9798-5:2009
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO/IEC 9798-2:2008
ОтменёнInformation technology — Security techniques — Entity authentication — Part 2: Mechanisms using symmetric enc…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…