ISO/IEC 10116:2017 PDF
Information technology — Security techniques — Modes of operation for an n-bit block cipher
Information technology — Security techniques — Modes of operation for an n-bit block cipher
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 39
- Дата публикации:
- 11 июля 2017 г.
- Издание:
- ISO/IEC IS 10116 edition 4 version 1
- ICS:
- 35.030
ISO/IEC 10116:2017 data during transmission or in storage). The defined modes only provide protection of data confidentiality. Protection of data integrity is not within the scope of this document. Also, most modes do not protect the confidentiality of message length information. NOTE 1 Methods for protecting the integrity of data using a block cipher are provided in ISO/IEC 9797-1. NOTE 2 Methods for simultaneously protecting the confidentiality and integrity of data are provided in ISO/IEC 19772. ISO/IEC 10116:2017 specifies the modes of operation and gives recommendations for choosing values of parameters (as appropriate). NOTE 3 The modes of operation specified in this document have been assigned object identifiers in accordance with ISO/IEC 9834. The list of assigned object identifiers is given in Annex A. In applications in which object identifiers are used, the object identifiers specified in Annex A are to be used in preference to any other object identifiers that can exist for the mode concerned. NOTE 4 Annex B contains comments on the properties of each mode and important security guidance.
Abstract
Overview
ISO/IEC 10116:2017 - Information technology - Security techniques - Modes of operation for an n‑bit block cipher - specifies five standardized modes of operation for n‑bit block ciphers used to protect data confidentiality (in transit or at rest). The document defines the operation, parameter choices and usage guidance for ECB, CBC, CFB, OFB and CTR modes. It covers padding and methods for avoiding ciphertext expansion, assigns object identifiers (OIDs) for each mode (Annex A), and provides properties and security guidance (Annex B), illustrative figures (Annex C) and numerical examples (Annex D).
Key topics and requirements
- Modes covered: Electronic Codebook (ECB), Cipher Block Chaining (CBC), Cipher Feedback (CFB), Output Feedback (OFB), Counter (CTR).
- Scope: Provides confidentiality only - integrity protection is explicitly out of scope. The standard notes that integrity mechanisms are provided in ISO/IEC 9797‑1 and combined confidentiality+integrity methods in ISO/IEC 19772.
- Parameter guidance: Recommendations for selecting parameters such as the starting variable (SV - analogous to IV), counter management for CTR, feedback buffer sizes and padding techniques are included.
- Padding and ciphertext expansion: Padding is within the normative scope; the 2017 edition added coverage for avoiding ciphertext expansion for CBC, CFB, OFB and CTR.
- Object identifiers (OIDs): Modes have assigned OIDs (Annex A) for consistent identification in protocols and implementations.
- Informative guidance: Annex B discusses per‑mode properties and important security considerations (e.g., risks of ECB, IV/counter reuse, synchronization requirements).
Applications and who uses it
ISO/IEC 10116:2017 is used by:
- Cryptographers and security architects designing encryption modules and protocols.
- Software engineers and library implementers building block‑cipher based encryption APIs.
- Network and systems engineers securing data in transit (VPNs, secure tunnels) and data at rest (disk encryption, secure storage).
- IoT and embedded device developers, especially when using lightweight block ciphers (see normative references).
- Standards bodies and compliance teams integrating OIDs and interoperable mode definitions into protocols.
Typical practical uses: selecting a mode for an encryption library, defining IV/counter handling in a protocol, implementing padding and ciphertext‑length handling, and ensuring cryptographic synchronization between sender and receiver.
Related standards
- ISO/IEC 9797‑1 - MACs / integrity mechanisms (referenced for integrity protection)
- ISO/IEC 19772 - authenticated encryption methods (confidentiality + integrity)
- ISO/IEC 18033‑3 and ISO/IEC 29192‑2 - block cipher algorithm references and lightweight block ciphers
Keywords: ISO/IEC 10116:2017, modes of operation, block cipher, ECB, CBC, CFB, OFB, CTR, data confidentiality, padding, ciphertext expansion, object identifiers.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 10116:2017
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 9797-1:2011/Amd 1:2023
ДействующийInformation technology — Security techniques — Message Authentication Codes (MACs) — Part 1: Mechanisms using…
Overview ISO/IEC 9797-1:2011/Amd 1:2023 is the latest amendment to the international standard for message authentication codes (MACs) that use block cipher mechanisms. Developed under ISO and IEC, th…
BS ISO/IEC 19772:2020
ДействующийInformation security. Authenticated encryption.
ISO/IEC 18033-3:2010/Amd 1:2021
ДействующийInformation technology — Security techniques — Encryption algorithms — Part 3: Block ciphers — Amendment 1: S…
Overview ISO/IEC 18033-3:2010/Amd 1:2021 is an important international standard amendment that expands the scope of encryption algorithms covered under Part 3 of ISO/IEC 18033-3, which focuses on blo…