Overview
ISO/IEC 18033-5:2015 - "Information technology - Security techniques - Encryption algorithms - Part 5: Identity‑based ciphers" specifies identity‑based encryption (IBE) mechanisms and their interfaces. The standard defines the functional behaviour, precise operation and ciphertext formats for identity‑based ciphers and identity‑based hybrid ciphers. It is part of the ISO/IEC 18033 series covering encryption algorithms and complements other parts that address asymmetric, block and stream ciphers.
Key SEO keywords: ISO/IEC 18033-5:2015, identity‑based encryption, IBE, identity‑based ciphers, identity‑based hybrid encryption, key encapsulation.
Key topics and technical requirements
- Functional interfaces and algorithms: Clear specification of the IBE algorithm components (set up, private key extraction, encryption, decryption) and identity‑based key encapsulation mechanisms.
- Specified mechanisms: The document includes the BF identity‑based encryption mechanism and two identity‑based key encapsulation mechanisms (SK and BB1).
- Cryptographic transforms: Definitions and required behaviour for helper functions and hash/transformation primitives referenced in the mechanisms (e.g., labeled functions such as IHF1, SHF1, PHF1 as described).
- Ciphertext format: A precise ciphertext format is specified for each mechanism; implementers may use alternative formats for storage/transmission provided conformance is maintained.
- System parameters and keys: Roles and requirements for system parameters, master‑secret key and corresponding master‑public key, and the Private Key Generator (PKG) that issues private keys.
- Identity‑based hybrid encryption: Model and composition rules for hybrid ciphers that combine identity‑based key encapsulation with data encapsulation primitives.
- Security and testing: Annexes provide object identifiers, security considerations, numerical examples/test vectors, and techniques to reduce PKG trust (mechanisms to prevent key access by third parties).
Practical applications and users
ISO/IEC 18033-5 is applicable where simplified public‑key discovery and reduced certificate management are desirable:
- Secure email and messaging using identity strings (e.g., email addresses) as public keys.
- Short‑lived encryption systems where frequent key rotation reduces reliance on revocation lists.
- IoT and constrained environments where certificate infrastructure is burdensome.
- Enterprise key management designs evaluating trust models involving a Private Key Generator (PKG).
Primary users:
- Cryptographers and security architects designing IBE solutions
- Software and hardware implementers of encryption libraries and protocols
- Standards bodies, auditors and security evaluators
Related standards
Note: ISO/IEC 18033‑5 describes trust implications of using a PKG and includes Annex D techniques to reduce PKG access; it does not prescribe external protocols for public value distribution or proof‑of‑possession.