ISO/IEC 9798-6:2010
Information technology — Security techniques — Entity authentication — Part 6: Mechanisms using manual data transfer
Information technology — Security techniques — Entity authentication — Part 6: Mechanisms using manual data transfer
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 35
- Дата публикации:
- 17 ноября 2010 г.
- Издание:
- ISO/IEC IS 9798 edition 2 version 1
- ICS:
- 35.030
ISO/IEC 9798-6:2010 specifies eight entity authentication mechanisms based on manual data transfer between authenticating devices. Four of these mechanisms are improved versions of mechanisms specified in ISO/IEC 9798-6:2005 since they use less user input and achieve more security. Such mechanisms can be appropriate in a variety of circumstances where there is no need for an existing public key infrastructure, shared secret keys or passwords. One such application occurs in personal networks, where the owner of two personal devices capable of wireless communications wishes them to perform an entity authentication procedure as part of the process of preparing them for use in the network. These mechanisms can also be used to support key management functions. ISO/IEC 9798-6:2010 specifies mechanisms in which entity authentication is achieved by manually transferring short data strings from one device to the other, or manually comparing short data strings output by the two devices. In ISO/IEC 9798-6:2010, the meaning of the term entity authentication is different from the meaning applied in other parts of ISO/IEC 9798. Instead of one device verifying that the other device has a claimed identity (and vice versa), both devices in possession of a user verify that they correctly share a data string with the other device at the time of execution of the mechanism. This data string could contain identifiers (and/or public keys) for one or both of the devices.
Abstract
Overview - ISO/IEC 9798-6:2010 (Entity authentication using manual data transfer)
ISO/IEC 9798-6:2010 specifies eight manual authentication mechanisms for entity authentication where two devices establish trust by manually transferring or comparing short data strings. Unlike other parts of ISO/IEC 9798, entity authentication here means both devices (in the possession of the same user) verify they share a common data string at the time of execution. The mechanisms are designed to work without an existing public key infrastructure, pre-shared secret keys, or passwords - making them suitable for device pairing and ad hoc personal networks.
Key technical topics and requirements
- Mechanism families:
- Mechanisms using a short check-value (Clause 6).
- Mechanisms using a short digest-value or short key (Clause 7).
- Mechanisms using a Message Authentication Code (MAC) (Clause 8).
- Total of eight mechanisms; four were improved in the 2010 edition to reduce user input and increase security vs. the 2005 edition.
- Interfaces and user interaction:
- Devices must have input/output interfaces; at minimum a simple input (e.g., one/two buttons) and simple output (e.g., LEDs).
- Standard input implies ability to enter short strings (numeric/hex/alphanumeric).
- Adversary model:
- Mechanisms assume the communications link can be fully compromised (active/passive attacks). Security relies on manual transfer or manual comparison of short strings.
- Functions and primitives:
- Check-value functions, digest functions, hash functions, and MAC algorithms are defined and constrained by properties in the standard.
- Practical guidance on parameter choices (short key lengths, digest lengths, MAC key sizes) is provided in Annexes D and F. The standard notes short keys are typically 4–6 digits and suggests digest-key sizes consistent with hash sizes (example: ~160 bits).
- Support materials:
- ASN.1 modules (Annex A), methods for generating short values (Annexes E, G), and analyses of security/efficiency (Annex F).
- Informative annexes show how manual mechanisms support secret key establishment (Annex B) and public key exchange (Annex C).
Practical applications and typical users
- Applications:
- Pairing personal devices (phones, headsets, wearables) and IoT device pairing where UX limits input but a user can confirm short strings.
- Ad hoc personal networks and scenarios with no PKI or pre-shared secrets.
- Supporting key management tasks such as establishing symmetric keys or reliably exchanging public keys and security parameters.
- Who should use this standard:
- Device manufacturers, firmware and mobile app developers implementing secure pairing.
- Security architects designing lightweight authentication for consumer devices.
- IoT product teams and standards implementers seeking compliant manual-authentication methods.
Related standards and references
- ISO/IEC 9798 (other parts: Part 1 general; Parts 2–5 for symmetric, signatures, etc.)
- ISO/IEC 9797-1 (MAC algorithms)
- ISO/IEC 10118-1 (hash functions)
- Annexes in ISO/IEC 9798-6 provide practical guidance for implementation and parameter selection.
Keywords: ISO/IEC 9798-6:2010, entity authentication, manual data transfer, manual authentication mechanisms, device pairing, key exchange, IoT device security.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 9798-6:2010
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 9798-2:2008
ОтменёнInformation technology — Security techniques — Entity authentication — Part 2: Mechanisms using symmetric enc…
ISO/IEC 9797-1:2011
ДействующийInformation technology — Security techniques — Message Authentication Codes (MACs) — Part 1: Mechanisms using…
Overview ISO/IEC 9797-1:2011 - Information technology - Security techniques - Message Authentication Codes (MACs) - Part 1: Mechanisms using a block cipher specifies six standardized MAC algorithms t…