Overview
ISO/IEC 15946-5:2022 - "Information security - Cryptographic techniques based on elliptic curves - Part 5: Elliptic curve generation" defines standard methods for generating elliptic curves suitable for secure cryptographic use. It is the third edition (2022) of this part of the ISO/IEC 15946 series and focuses on generation techniques for elliptic curve cryptography (ECC) over finite fields of prime power order (including prime order and characteristic two). The document does not prescribe how finite field elements are represented (choice of basis).
Key topics and technical requirements
- Framework and conventions: definitions, symbols, conversion functions, and group law conventions for elliptic curves over F(p), F(2^m) and F(3^m).
- Verifiably pseudo-random curve generation:
- Algorithms for constructing verifiably pseudo-random curves in the prime and binary field cases.
- Tests and procedures: near-primality testing, finding points of large prime order, and verification of pseudo-randomness.
- Complex multiplication (CM) method:
- Prescribed CM techniques for constructing curves including treatment of pairing‑friendly curves.
- Specific examples and guidance for Barreto–Naehrig (BN) and Barreto–Lynn‑Scott (BLS) families.
- Lifting methods: techniques for constructing curves by lifting from smaller fields.
- Security considerations and examples:
- Annexes provide background on ECC, pairing security (including recent concerns such as exTNFS for some BN curve parameters), numerical examples and property summaries.
- Interoperability rules: guidance to ensure generated curves are suitable for use in standardized cryptographic mechanisms.
Applications
ISO/IEC 15946-5:2022 is intended to support secure key management, digital signatures, public-key encryption, and pairing-based protocols. It supplies curve generation techniques usable by implementations of other standards such as:
Practical uses include:
- Generating standardized, verifiable ECC domain parameters for cryptographic libraries
- Selecting or creating pairing-friendly curves (BN, BLS) with documented security properties
- Producing curves for constrained devices and lightweight cryptography where parameter size matters
Who should use this standard
- Cryptographic engineers and protocol designers
- Security architects and system integrators
- Cryptographic library and hardware token implementers
- Standards bodies and auditors evaluating curve generation and parameter provenance
Related standards
Keywords: elliptic curve generation, ECC, elliptic curve cryptography, verifiably pseudo-random curves, complex multiplication, BN curves, BLS curves, finite fields, ISO/IEC 15946-5.