ISO/IEC 14888-4:2024 PDF
Information security — Digital signatures with appendix — Part 4: Stateful hash-based mechanisms
Information security — Digital signatures with appendix — Part 4: Stateful hash-based mechanisms
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 56
- Дата публикации:
- 24 июня 2024 г.
- Издание:
- ISO/IEC IS 14888 edition 1 version 1
- ICS:
- 35.030
This document specifies stateful digital signature mechanisms with appendix, where the level of security is determined by the security properties of the underlying hash function. This document also provides requirements for implementing basic state management, which is needed for the secure deployment of the stateful schemes described in this document.
Abstract
Overview - ISO/IEC 14888-4:2024
ISO/IEC 14888-4:2024 specifies stateful hash-based digital signature mechanisms with appendix. First published in 2024 as Part 4 of the ISO/IEC 14888 series, this international standard defines hash-based signature schemes whose security depends solely on the strength of the underlying hash function. Because these schemes are stateful, the standard also provides requirements and guidance for basic state management needed to safely deploy the described algorithms.
Keywords: ISO/IEC 14888-4, stateful hash-based signatures, post-quantum digital signatures, XMSS, LMS, HSS, WOTS+, Merkle tree, state management.
Key technical topics and requirements
- Hash-based signature families covered
- XMSS and XMSS-MT (eXtended Merkle Signature Scheme and multi-tree variant)
- LMS and HSS (Leighton–Micali Signature and Hierarchical Signature Scheme)
- Auxiliary one-time schemes such as WOTS+ and LM-OTS
- Core building blocks and algorithms
- Definitions and algorithms for key generation, signing, verification, and authentication path computation
- Use of Merkle trees, L-tree structures, and Winternitz parameters
- State management
- Mandatory requirements to update and protect signer state (private-key usage counters, indices, etc.) to prevent reuse that would compromise security
- Guidance aimed at robust deployment to avoid forgery due to incorrect state handling
- Supporting material
- Suggested parameter sets, byte order conventions, checksum methods, and ASN.1 object identifiers/module (Annex A)
- Informative annexes with relations to other standards and numerical examples
Note: The standard intentionally ties security to the cryptographic hash function chosen; it does not introduce new hash primitives.
Practical applications and who should use it
- Use cases
- Post-quantum-resilient digital signatures for software and firmware signing, secure boot, software distribution, code-signing, long-term archival integrity, and secure logging
- Signature solutions for constrained or embedded systems where hash-based schemes are attractive
- Primary users
- Security architects, cryptographic engineers, PKI operators, firmware and IoT device vendors, standards bodies, and implementers seeking quantum-resistant signature options
- Benefits
- Predictable security based on hash function properties and standardized algorithms for interoperable implementations
Related standards
- Part of the ISO/IEC 14888 family (see Parts 2 and 3 for algorithm classes based on integer factorization and discrete logarithms). Annex B of 14888-4 discusses relations to other standards and deployment considerations.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 14888-4:2024
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS ISO/IEC 14888-4:2024
ДействующийInformation security. Digital signatures with appendix. Stateful hash-based mechanisms.
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…
ISO/ASTMTR52917-EB
ДействующийAdditive Manufacturing — Round Robin Testing — General Guidelines
This document outlines the steps with regard to aspects of design to conduct and run a round robin study (RRS) to assess the degree of variability in an additive manufacturing material or process. Th…