ISO/IEC 11770-6:2016 PDF
Information technology — Security techniques — Key management — Part 6: Key derivation
Information technology — Security techniques — Key management — Part 6: Key derivation
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 23
- Дата публикации:
- 5 октября 2016 г.
- Издание:
- ISO/IEC IS 11770 edition 1 version 1
- ICS:
- 35.030
ISO/IEC 11770-6:2016 specifies key derivation functions, i.e. functions which take secret information and other (public) parameters as input and output one or more "derived" secret keys. Key derivation functions based on MAC algorithms and on hash-functions are specified.
Abstract
Overview
ISO/IEC 11770-6:2016 - "Information technology - Security techniques - Key management - Part 6: Key derivation" specifies standardized key derivation functions (KDFs) that produce one or more secret keys from existing secret input plus public parameters. The standard defines both MAC‑based and hash‑based KDF constructions, and describes models, notation, and relationships to the key management life cycle. It is part of the ISO/IEC 11770 key management series.
Key topics and requirements
- One‑step vs Two‑step KDFs
- One‑step KDFs (OKDF1…OKDF6): transform secret input directly into key(s) in a single operation - typically used when the input is already a secret key or the function is used only once.
- Two‑step KDFs: separate key extraction (e.g., KTF1) and key expansion (KPF1…KPF4) phases. The extraction produces a MAC key; expansion generates application keys (examples: TKDF1…TKDF4).
- Cryptographic primitives
- KDFs defined using Message Authentication Codes (MACs) and hash functions. Normative references include ISO/IEC 9797 (MACs) and ISO/IEC 10118 (hash‑functions).
- Security considerations
- Treatment of entropy, confidentiality of derived keys, use of non‑secret parameters (labels, context), and safe reuse rules.
- Guidance on choosing one‑step vs two‑step based on input entropy and reuse.
- Structure and guidance
- Formal notation, object identifiers (Annex A), and informative guidance for correct use (Annex B).
Applications
ISO/IEC 11770-6 provides practical, interoperable KDF specifications for:
- Deriving encryption and MAC keys from pre‑existing secrets (passwords, master keys, shared secrets)
- Generating multiple purpose keys (separation of keys for encryption, authentication, session handling)
- Improving entropy/uniformity of non‑ideal secret material via extraction
- Key management in constrained devices, secure storage, and secure communications where standardized KDFs are required
Who should use this standard
- Cryptographic library implementers and protocol designers
- Security architects and engineers designing key management schemes
- Certification and compliance teams validating KDF usage
- Vendors of secure hardware, IoT devices, and enterprise security products
Related standards
- ISO/IEC 11770 (series) - Key management
- ISO/IEC 9797 - Message Authentication Codes (MACs)
- ISO/IEC 10118 - Hash‑functions
- ISO/IEC 11770‑1 - Key management terms and concepts
Using ISO/IEC 11770-6:2016 helps ensure secure, interoperable key derivation practices by specifying vetted MAC‑ and hash‑based KDF constructions and clear guidance for practical deployment.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 11770-6:2016
Похожие стандарты
Стандарты, упомянутые в описании
BS ISO/IEC 11770-2:2018
ДействующийIT Security techniques. Key management. Mechanisms using symmetric techniques.
ISO/IEC 9797-1:2011/Amd 1:2023
ДействующийInformation technology — Security techniques — Message Authentication Codes (MACs) — Part 1: Mechanisms using…
Overview ISO/IEC 9797-1:2011/Amd 1:2023 is the latest amendment to the international standard for message authentication codes (MACs) that use block cipher mechanisms. Developed under ISO and IEC, th…
ISO/IEC 10118-1:2016/Amd 1:2021
ДействующийInformation technology — Security techniques — Hash-functions — Part 1: General — Amendment 1: Padding method…
Overview ISO/IEC 10118-1:2016/Amd 1:2021 is an important amendment to the international standard covering information technology security techniques related to hash functions. This amendment specific…
ISO/IEC 11770-1:2010
ДействующийInformation technology — Security techniques — Key management — Part 1: Framework
Overview ISO/IEC 11770-1:2010 - Information technology - Security techniques - Key management - Part 1: Framework - defines a vendor‑ and algorithm‑neutral key management framework. It establishes a…