ISO/IEC 11770-3:2021 PDF
Information security — Key management — Part 3: Mechanisms using asymmetric techniques
Information security — Key management — Part 3: Mechanisms using asymmetric techniques
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 90
- Дата публикации:
- 22 октября 2021 г.
- Издание:
- ISO/IEC IS 11770 edition 4 version 1
- ICS:
- 35.030
This document defines key management mechanisms based on asymmetric cryptographic techniques. It specifically addresses the use of asymmetric techniques to achieve the following goals. a) Establish a shared secret key for use in a symmetric cryptographic technique between two entities A and B by key agreement. In a secret key agreement mechanism, the secret key is computed as the result of a data exchange between the two entities A and B. Neither of them is able to predetermine the value of the shared secret key. b) Establish a shared secret key for use in a symmetric cryptographic technique between two entities A and B via key transport. In a secret key transport mechanism, the secret key is chosen by one entity A and is transferred to another entity B, suitably protected by asymmetric techniques. c) Make an entity's public key available to other entities via key transport. In a public key transport mechanism, the public key of entity A is transferred to other entities in an authenticated way, but not requiring secrecy. Some of the mechanisms of this document are based on the corresponding authentication mechanisms in ISO/IEC 9798‑3. This document does not cover certain aspects of key management, such as: — key lifecycle management; — mechanisms to generate or validate asymmetric key pairs; and — mechanisms to store, archive, delete, destroy, etc., keys. While this document does not explicitly cover the distribution of an entity's private key (of an asymmetric key pair) from a trusted third party to a requesting entity, the key transport mechanisms described can be used to achieve this. A private key can in all cases be distributed with these mechanisms where an existing, non-compromised key already exists. However, in practice the distribution of private keys is usually a manual process that relies on technological means such as smart cards, etc. This document does not specify the transformations used in the key management mechanisms. NOTE To provide origin authentication for key management messages, it is possible to make provisions for authenticity within the key establishment protocol or to use a public key signature system to sign the key exchange messages.
Abstract
Overview
ISO/IEC 11770-3:2021 - Information security - Key management - Part 3: Mechanisms using asymmetric techniques - defines standardized key management mechanisms that use asymmetric (public‑key) cryptography. The standard covers mechanisms to:
- Establish shared symmetric keys by key agreement (neither party can predetermine the result),
- Transport secret keys (one party chooses a key and securely transfers it to another), and
- Transport public keys in an authenticated (but not secret) manner.
It addresses mechanisms based on finite fields, elliptic curves and bilinear pairings, and includes many concrete mechanism templates and informative examples (including elliptic‑curve examples and pairing‑based examples). The 2021 edition introduces additions such as blinded Diffie‑Hellman mechanisms and an SM9 example.
Key topics and requirements
ISO/IEC 11770-3:2021 focuses on functional and protocol-level mechanisms rather than low‑level transforms. Major technical topics include:
- Key agreement mechanisms (15 variants described, with properties and examples)
- Secret key transport mechanisms (multiple transport mechanisms and examples)
- Public key transport mechanisms (authenticated public key distribution)
- Key derivation functions and examples (used to derive session keys from shared material)
- Cofactor multiplication, key commitment and key confirmation procedures
- A framework for two‑ and three‑party key establishment
- Normative object identifiers and informative annexes with worked examples
The standard explicitly does not cover key lifecycle management, key pair generation/validation processes, or key storage/archival/destruction mechanisms. It also notes that origin authentication can be provided either within a protocol or by using digital signatures.
Practical applications
ISO/IEC 11770-3:2021 is practical for designing, documenting and assessing cryptographic key establishment components of systems such as:
- Secure messaging and VPN protocols
- Transport and session key establishment for TLS-like or custom protocols
- IoT device onboarding and secure provisioning
- PKI and HSM integration where asymmetric techniques bootstrap symmetric session keys
- Secure multi‑party or group key establishment schemes
The standard helps implementers choose and compose well‑understood asymmetric key establishment primitives while ensuring interoperability and consistent security properties.
Who should use this standard
- Cryptographic engineers and protocol designers
- Security architects and system integrators
- Product vendors implementing key establishment (software, devices, HSMs)
- Auditors and compliance teams evaluating key management mechanisms
- Standards bodies and technical writers referencing interoperable mechanisms
Related standards & notes
- Related parts: ISO/IEC 11770 series (Part 1 framework, Part 6 key derivation)
- Cross‑references: ISO/IEC 9798‑3 (authentication mechanisms)
- Security practitioners should note the document’s patent caution and consult the ISO/IEC patent database if required.
Keywords: ISO/IEC 11770-3:2021, key management, asymmetric techniques, key agreement, key transport, public key transport, elliptic curve, Diffie‑Hellman, bilinear pairings.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 11770-3:2021
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS ISO/IEC 11770-2:2018
ДействующийIT Security techniques. Key management. Mechanisms using symmetric techniques.
ISO/IEC 9798-3:1998/Amd 1:2010
ОтменёнInformation technology — Security techniques — Entity authentication — Part 3: Mechanisms using digital signa…
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…