ISO/IEC 11770-1:2010 PDF
Information technology — Security techniques — Key management — Part 1: Framework
Information technology — Security techniques — Key management — Part 1: Framework
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 30
- Дата публикации:
- 22 ноября 2010 г.
- Издание:
- ISO/IEC IS 11770 edition 2 version 1
- ICS:
- 35.030
ISO/IEC 11770-1:2010 defines a general model of key management that is independent of the use of any particular cryptographic algorithm. However, certain key distribution mechanisms can depend on particular algorithm properties, for example, properties of asymmetric algorithms. ISO/IEC 11770-1:2010 contains the material required for a basic understanding of subsequent parts. Examples of the use of key management mechanisms are included in ISO 11568. If non-repudiation is required for key management, ISO/IEC 13888 is applicable. ISO/IEC 11770-1:2010 addresses both the automated and manual aspects of key management, including outlines of data elements and sequences of operations that are used to obtain key management services. However it does not specify details of protocol exchanges that might be needed. As with other security services, key management can only be provided within the context of a defined security policy. The definition of security policies is outside the scope of ISO/IEC 11770. The fundamental problem is to establish keying material whose origin, integrity, timeliness and (in the case of secret keys) confidentiality can be guaranteed to both direct and indirect users. Key management includes functions such as the generation, storage, distribution, deletion and archiving of keying material in accordance with a security policy (ISO 7498-2). ISO/IEC 11770-1:2010 has a special relationship to the security frameworks for open systems (ISO/IEC 10181). All the frameworks, including this one, identify the basic concepts and characteristics of mechanisms covering different aspects of security.
Abstract
Overview
ISO/IEC 11770-1:2010 - Information technology - Security techniques - Key management - Part 1: Framework - defines a vendor‑ and algorithm‑neutral key management framework. It establishes a general model and terminology for managing cryptographic keying material across its life cycle, covering both automated and manual aspects (but not low‑level protocol exchanges). The standard is intended as the foundational reference for subsequent parts of ISO/IEC 11770 and for designers of secure systems and key management services.
Key topics and technical requirements
- General model and terminology: definitions for keys, keying material, key agreement, key transport, certification authority, and related concepts.
- Key life cycle model: states and transitions (generation, registration, distribution, installation, storage, archiving, revocation, deregistration, destruction).
- Key management services: standardized service concepts including Generate‑Key, Register‑Key, Create‑Key‑Certificate, Distribute‑Key, Install‑Key, Store‑Key, Derive‑Key, Archive‑Key, Revoke‑Key, Deregister‑Key, Destroy‑Key.
- Protection mechanisms: guidelines for protecting keys by cryptographic, non‑cryptographic, physical and organisational means.
- Conceptual key distribution models: distribution between two entities, within a domain, and between domains; includes roles such as key distribution centre and key translation centre.
- Support services: key management facility and user‑oriented support functions.
- Threats and information objects: informative annexes cover typical threats to key management and key management data elements.
- Scope constraints: focuses on architecture and services; does not mandate specific cryptographic algorithms or protocol message formats.
Applications and who uses it
ISO/IEC 11770-1:2010 is used by:
- Security architects and system designers building Key Management Systems (KMS), Public Key Infrastructures (PKI), HSM integrations and cloud key management.
- Product developers of secure devices (smart cards, TPMs, HSMs) and software implementing key lifecycle controls.
- Enterprise security teams and DevOps designing key rotation, storage and distribution policies for cloud, IoT and messaging systems.
- Compliance officers and auditors mapping organizational security policy to standard key management practices. Practical applications include secure key generation, certificate lifecycle planning, cross‑domain key exchange models, and establishing organizational controls for key storage, archival and secure destruction.
Related standards
- ISO/IEC 11770 series - Part 2 (symmetric mechanisms), Part 3 (asymmetric mechanisms), Part 4 (weak secrets), Part 5 (group key management - under preparation).
- ISO/IEC 10181 (security frameworks for open systems), ISO 11568 (examples of key management mechanisms), ISO/IEC 13888 (non‑repudiation for key management), ISO 7498‑2 (security policy context).
Keywords: ISO/IEC 11770-1:2010, key management framework, key lifecycle, cryptographic keys, key distribution, key generation, key storage, PKI, KMS, security policy.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 11770-1:2010
Похожие стандарты
Стандарты, упомянутые в описании
BS ISO/IEC 11770-2:2018
ДействующийIT Security techniques. Key management. Mechanisms using symmetric techniques.
ISO/IEC 10181-5:1996
ДействующийInformation technology — Open Systems Interconnection — Security frameworks for open systems: Confidentiality…
Overview - ISO/IEC 10181-5:1996 (Confidentiality framework) ISO/IEC 10181-5:1996 defines a general framework for confidentiality services within Open Systems Interconnection (OSI). Published as part…