ISO/IEC 20009-2:2013 PDF
Information technology — Security techniques — Anonymous entity authentication — Part 2: Mechanisms based on signatures using a group public key
Information technology — Security techniques — Anonymous entity authentication — Part 2: Mechanisms based on signatures using a group public key
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 51
- Дата публикации:
- 27 ноября 2013 г.
- Издание:
- ISO/IEC IS 20009 edition 1 version 1
- ICS:
- 35.030
ISO/IEC 20009-2:2013 specifies anonymous entity authentication mechanisms based on signatures using a group public key in which a verifier verifies a group signature scheme to authenticate the entity with which it is communicating, without knowing this entity's identity. ISO/IEC 20009-2:2013 provides: a general description of an anonymous entity authentication mechanism based on signatures using a group public key; a variety of mechanisms of this type. ISO/IEC 20009-2:2013 describes: the group membership issuing processes; anonymous authentication mechanisms without an online Trusted Third Party (TTP); anonymous authentication mechanisms involving an online TTP. Furthermore, ISO/IEC 20009-2:2013 also specifies: the group membership opening process (optional); the group signature linking process (optional).
Abstract
Overview
ISO/IEC 20009-2:2013 - Information technology - Security techniques - Anonymous entity authentication - Part 2: Mechanisms based on signatures using a group public key - defines anonymous authentication mechanisms that rely on group signatures (anonymous signatures using a group public key). The standard specifies how a verifier can confirm that a claimant is an authorized member of a group without learning the claimant’s identity. It covers general models, key generation, membership issuing, and optional operations such as opening and linking of group signatures.
Key topics and technical requirements
- Group signature-based authentication: Tokens are generated as group signatures; verifiers validate the signature against a group public key without identifying the signer.
- Group membership processes: Procedures for issuing and managing group membership and group public key certificates.
- Mechanisms without an online TTP: Flows for unilateral and mutual anonymous authentication where no trusted third party is required online.
- Mechanisms involving an online TTP: Variants that use an online Trusted Third Party to support issuance, authentication, or revocation.
- Optional opening and linking: Definitions of the group membership opening process (to reveal identity under controlled conditions) and group signature linking (to detect multiple signatures from the same member), including local linking and linking-key approaches.
- Binding-property support: Mechanisms that bind authentication tokens to session-specific data (messages, ephemeral keys) to prevent replay or misuse.
- Key management and cryptographic context: Key generation and key derivation functions, group public key certificates, ephemeral key pairs, and references to cryptographic assumptions (e.g., groups where the DDH problem is hard).
- Normative references: Integrates with ISO/IEC 20008 series (anonymous signatures) and ISO/IEC 20009-1 (general).
Note: the standard draws attention to possible patent-encumbered methods; implementers should review patent statements and licensing.
Practical applications and who uses it
ISO/IEC 20009-2:2013 is relevant for:
- Security architects and system integrators designing privacy-preserving authentication for online services.
- Identity providers and certification authorities that manage group public keys and membership issuance.
- Developers of privacy-enhancing technologies such as anonymous credential systems, e-voting, privacy-preserving access control, and anonymous audit/logging.
- Vendors of authentication platforms requiring anonymous or pseudonymous user proof-of-membership.
- Regulatory and standards teams assessing privacy and accountability trade-offs (e.g., optional opener for lawful disclosure).
Related standards
- ISO/IEC 20009-1: General anonymous entity authentication
- ISO/IEC 20008-2: Anonymous digital signatures - Mechanisms using a group public key
- Future parts (blind signatures, weak secrets) expand alternative anonymous authentication mechanisms
Keywords: ISO/IEC 20009-2:2013, anonymous entity authentication, group public key, group signature, anonymous authentication, security techniques, Trusted Third Party, group membership, binding-property.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 20009-2:2013
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO/IEC 20008-2:2013/Amd 2:2023
ДействующийInformation technology — Security techniques — Anonymous digital signatures — Part 2: Mechanisms using a grou…
Overview ISO/IEC 20008-2:2013/Amd 2:2023 - "Information technology - Security techniques - Anonymous digital signatures - Part 2: Mechanisms using a group public key (Amendment 2)" updates the Part 2…
ISO/IEC 20009-1:2013
ДействующийInformation technology — Security techniques — Anonymous entity authentication — Part 1: General
Overview ISO/IEC 20009-1:2013 - "Information technology - Security techniques - Anonymous entity authentication - Part 1: General" defines a model, terminology, requirements and constraints for anony…
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…