ISO/IEC 10118-3:2018 PDF
IT Security techniques — Hash-functions — Part 3: Dedicated hash-functions
IT Security techniques — Hash-functions — Part 3: Dedicated hash-functions
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 398
- Дата публикации:
- 31 октября 2018 г.
- Издание:
- ISO/IEC IS 10118 edition 4 version 1
- ICS:
- 35.030
This document specifies dedicated hash-functions, i.e. specially designed hash-functions. The hash-functions in this document are based on the iterative use of a round-function. Distinct round-functions are specified, giving rise to distinct dedicated hash-functions. The use of Dedicated Hash-Functions 1, 2 and 3 in new digital signature implementations is deprecated. NOTE As a result of their short hash-code length and/or cryptanalytic results, Dedicated Hash-Functions 1, 2 and 3 do not provide a sufficient level of collision resistance for future digital signature applications and they are therefore, only usable for legacy applications. However, for applications where collision resistance is not required, such as in hash-functions as specified in ISO/IEC 9797‑2, or in key derivation functions specified in ISO/IEC 11770‑6, their use is not deprecated. Numerical examples for dedicated hash-functions specified in this document are given in Annex B as additional information. For information purposes, SHA-3 extendable-output functions are specified in Annex C.
Abstract
Overview
ISO/IEC 10118-3:2018 - IT Security techniques - Hash-functions - Part 3: Dedicated hash‑functions specifies a set of specially designed (dedicated) cryptographic hash‑functions. The standard defines these algorithms in detail: their models, parameters, byte ordering, padding methods, constants, initialization values and the iterative round‑function descriptions used to compute hash codes. Annex B provides numerical examples and Annex C includes SHA‑3 extendable‑output functions for information.
Key technical topics and requirements
- Models and design: Defines both a round‑function model (iterative construction) and a sponge model for dedicated hash‑function design and use.
- Algorithm specifications: Exact descriptions for multiple dedicated hash‑functions (e.g., RIPEMD‑160, RIPEMD‑128, SHA‑1, SHA‑224, SHA‑256, SHA‑384, SHA‑512, WHIRLPOOL, SHA‑512/224, etc.) including:
- Parameters, functions and constants
- Byte ordering conventions
- Padding methods
- Initializing values
- Detailed round‑function operation and sequence
- Security guidance: Notes deprecation of Dedicated Hash‑Functions 1, 2 and 3 (RIPEMD‑160, RIPEMD‑128, SHA‑1 as listed) for new digital signature implementations due to short hash lengths and known cryptanalytic weaknesses. Their use remains allowed for legacy systems and for applications where collision resistance is not required (for example, certain MACs or KDFs per ISO/IEC 9797‑2 and ISO/IEC 11770‑6).
- Annexes: Numerical examples (Annex B) to aid implementers and SHA‑3 XOF information (Annex C).
Practical applications and who uses this standard
ISO/IEC 10118-3 is intended for:
- Cryptographic library implementers and software developers who need authoritative, interoperable definitions of hash algorithms.
- Security architects and protocol designers specifying hash functions for messaging, file integrity, key derivation or MAC constructions.
- Product vendors and embedded systems developers implementing legacy support or compliance with existing deployments.
- Evaluators, auditors and standards compliance officers verifying correct algorithm implementation and conformance.
- Educators and researchers referencing formal algorithm definitions and example vectors.
Use cases:
- Legacy system maintenance where older hash algorithms remain deployed.
- KDFs and MACs where collision resistance is not a primary requirement (per ISO/IEC 9797‑2, ISO/IEC 11770‑6).
- Implementations requiring exact algorithmic parameters, padding and byte‑order rules for interoperability.
Related standards
- ISO/IEC 10118‑1 (symbols and general provisions referenced)
- ISO/IEC 9797‑2 (message authentication codes)
- ISO/IEC 11770‑6 (key derivation)
- SHA‑3 specifications (referenced in Annex C for extendable‑output functions)
Keywords: ISO/IEC 10118-3, dedicated hash-functions, hash function standard, SHA-1 deprecation, RIPEMD, WHIRLPOOL, cryptographic hash, IT security techniques, collision resistance.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 10118-3:2018
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 9797-2:2002
ОтменёнInformation technology — Security techniques — Message Authentication Codes (MACs) — Part 2: Mechanisms using…
ISO/IEC 11770-6:2016
ДействующийInformation technology — Security techniques — Key management — Part 6: Key derivation
Overview ISO/IEC 11770-6:2016 - "Information technology - Security techniques - Key management - Part 6: Key derivation" specifies standardized key derivation functions (KDFs) that produce one or mor…
ISO/IEC 10118-3:2004/Amd 1:2006
ОтменёнInformation technology — Security techniques — Hash-functions — Part 3: Dedicated hash-functions — Amendment…
ISO/IEC 10118-1:2016/Amd 1:2021
ДействующийInformation technology — Security techniques — Hash-functions — Part 1: General — Amendment 1: Padding method…
Overview ISO/IEC 10118-1:2016/Amd 1:2021 is an important amendment to the international standard covering information technology security techniques related to hash functions. This amendment specific…