ISO/IEC 20008-1:2013 PDF
Information technology — Security techniques — Anonymous digital signatures — Part 1: General
Information technology — Security techniques — Anonymous digital signatures — Part 1: General
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 20
- Дата публикации:
- 9 декабря 2013 г.
- Издание:
- ISO/IEC IS 20008 edition 1 version 1
- ICS:
- 35.030
ISO/IEC 20008-1:2013 specifies principles, including a general model, a set of entities, a number of processes, and general requirements for the following two categories of anonymous digital signature mechanisms: signature mechanisms using a group public key, and signature mechanisms using multiple public keys.
Abstract
Overview
ISO/IEC 20008-1:2013 - Information technology - Security techniques - Anonymous digital signatures - Part 1: General defines the principles, models and general requirements for anonymous digital signature mechanisms. It covers two broad categories: mechanisms using a group public key (group signatures) and mechanisms using multiple public keys (ring signatures). The standard establishes a common vocabulary, entity roles, processes (key generation, signing, verification) and high-level security requirements for anonymity and verifiability.
Key Topics
- General model and entities: group, group member, group membership issuer, evidence evaluator, verifier, etc.
- Core processes: key generation, group membership issuing, signature creation, signature verification.
- Specialized processes for group signatures: group membership opening (to reveal signer under authorised conditions), signature linking, and revocation procedures.
- Anonymity strength: defined as the probability measure that an unauthorised party can correctly identify the signer (e.g., anonymity strength n means probability 1/n).
- Revocation levels for group public-key mechanisms:
- revoke an entire group,
- revoke a specific member’s membership,
- revoke authorization for a member to create specific signature types.
- Evidence of binding and evidence evaluation: mechanisms to produce and check data that ties a signature to a signer for authorised parties while preserving anonymity against unauthorised observers.
- Security foundations: reliance on well-known intractability assumptions (factorization, discrete logarithm) and use of standard crypto primitives such as collision-resistant hash functions and conventional signature/encryption mechanisms where required.
Applications and Who Uses It
ISO/IEC 20008-1:2013 is aimed at organizations and professionals building privacy-preserving authentication and signing systems:
- Security architects and cryptographic engineers designing anonymous authentication, e-voting, privacy-preserving audit logs, and anonymous credential systems.
- PKI operators and membership authorities managing group issuance, revocation and policy enforcement.
- Protocol designers and software vendors who implement group/ring signature schemes or integrate them into messaging, identity and blockchain solutions.
- Standards bodies and compliance teams aligning implementations with international security requirements.
Benefits include standardized terminology, clear process models for group-based anonymity, and guidance on controlled de-anonymization and revocation.
Related Standards
- ISO/IEC 20008-2 (mechanisms using a group public key)
- ISO/IEC 20009 (anonymous entity authentication)
- ISO/IEC 10118 (hash-functions), ISO/IEC 9796 / 14888 (digital signatures), ISO/IEC 9798 (entity authentication), ISO/IEC 18033-2 (asymmetric encryption)
This part provides the foundational framework for implementing anonymous digital signatures in information technology security solutions.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 20008-1:2013
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 20008-2:2013/Amd 2:2023
ДействующийInformation technology — Security techniques — Anonymous digital signatures — Part 2: Mechanisms using a grou…
Overview ISO/IEC 20008-2:2013/Amd 2:2023 - "Information technology - Security techniques - Anonymous digital signatures - Part 2: Mechanisms using a group public key (Amendment 2)" updates the Part 2…
BS ISO/IEC 20009-2:2013
ДействующийInformation technology. Security techniques. Anonymous entity authentication. Mechanisms based on signatures…
ISO/IEC 10118-1:2016/Amd 1:2021
ДействующийInformation technology — Security techniques — Hash-functions — Part 1: General — Amendment 1: Padding method…
Overview ISO/IEC 10118-1:2016/Amd 1:2021 is an important amendment to the international standard covering information technology security techniques related to hash functions. This amendment specific…
ISO/IEC 9796-2:2002/Amd 1:2008
ОтменёнInformation technology — Security techniques — Digital signature schemes giving message recovery — Part 2: In…
ISO/IEC 9798-4:1999/Cor 2:2012
ДействующийInformation technology — Security techniques — Entity authentication — Part 4: Mechanisms using a cryptograph…
Overview ISO/IEC 9798-4:1999/Cor 2:2012 is a technical corrigendum issued by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) to update…
ISO/IEC 18033-2:2006/Amd 1:2017
ДействующийInformation technology — Security techniques — Encryption algorithms — Part 2: Asymmetric ciphers — Amendment…
Overview ISO/IEC 18033-2:2006/Amd 1:2017 is an international standard from ISO and IEC addressing information technology security, with a focus on encryption algorithms for asymmetric ciphers. This a…