ISO/IEC 20248:2022 PDF
Information technology — Automatic identification and data capture techniques — Digital signature data structure schema
Information technology — Automatic identification and data capture techniques — Digital signature data structure schema
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 106
- Дата публикации:
- 10 июня 2022 г.
- Издание:
- ISO/IEC IS 20248 edition 2 version 1
- ICS:
- 35.040.50
This document is an ISO/IEC 9594‑8 [public key infrastructure (PKI) digital signatures and certificates] application specification for automated identification services. It specifies a method whereby data stored within a barcode and/or RFID tag are structured, encoded and digitally signed. ISO/IEC 9594‑8 is used to provide a standard method for key and data description management and distribution. The data capacity and/or data transfer capacity of automated identification data carriers are restricted. This restricts the normal use of a digital signature as specified in ISO/IEC 9594‑8 within automated identification services. The purpose of this document is to provide an open and interoperable method, between automated identification services and data carriers, to read data, verify data originality and data integrity in an offline use case. This document specifies — the meta data structure, the DigSig, which contains the digital signature and encoded structured data, — the public key certificate parameter and extension use, the DigSig certificate, which contains the certified associated public key, the structured data description, the read methods, and private containers, — the method to specify, read, describe, sign, verify, encode, and decode the structured data, the DigSig Data Description, — the DigSig EncoderGenerator which generates the relevant asymmetric key pairs, keeps the private key secret, and generates the DigSigs, and — the DigSig DecoderVerifier which, by using to the DigSig certificate, reads the DigSig from the set of data carriers, verifies the DigSig and extracts the structured data from the DigSig. This document does not specify — cryptographic methods, or — key management methods.
Abstract
Overview
ISO/IEC 20248:2022 specifies a standardized digital signature data structure schema (commonly called a DigSig) for automatic identification and data capture (AIDC) technologies such as barcodes and RFID tags. Designed as an application specification of ISO/IEC 9594‑8 (PKI digital signatures and certificates), the standard enables compact, interoperable packaging of structured data and a digital signature so that data can be read and verified offline from constrained data carriers.
Key goals:
- Enable reading, authenticity verification and integrity checks of encoded AIDC data in offline use cases
- Provide an open, interoperable method for structuring, encoding and signing AIDC payloads
- Accommodate limited data capacity and transfer rates typical of barcodes and RFID
Key topics and technical requirements
- DigSig structure: a meta-data envelope which contains the encoded structured data and the digital signature.
- DigSig certificate: an application of PKI certificate parameters and extensions to carry the certified public key used to verify DigSigs.
- DigSig Data Description (DDD): defines how structured data fields are specified, encoded, displayed and parsed for signing/verification.
- EncoderGenerator and DecoderVerifier: device/process roles - EncoderGenerator creates asymmetric key pairs, keeps private keys secret, and generates DigSigs; DecoderVerifier uses DigSig certificates to read and verify DigSigs and extract structured data.
- Read methods, private containers, envelope formats, and presentation: covers pragmatic encoding constructs (e.g., “snips”, DDDdata, SigData, DDDdataDisplay) and directives for constrained carriers.
- Conformance, test methods and error codes: conformance claims, test specifications and standardized error reporting are included.
- Important exclusions: the standard does not prescribe specific cryptographic algorithms or key management methods.
Practical applications and intended users
ISO/IEC 20248 is valuable for:
- Supply chain and logistics providers who need tamper-evident barcodes/RFID with offline authenticity checks
- Manufacturers and developers of AIDC readers, mobile verification apps and IoT devices
- Certificate authorities and system integrators implementing DigSig certificate processes
- Healthcare, government credentials, product authentication, anti-counterfeiting and document security use cases requiring compact signed payloads
Benefits include increased data integrity, offline verification capability, and cross-vendor interoperability for constrained AIDC media.
Related standards
- ISO/IEC 9594‑8 - PKI digital signatures and certificates (application base)
- ISO/IEC 15434, ISO/IEC 18000‑63, and GS1 EPC Gen2 - referenced in annexes for example message and RFID usages
- Other ISO AIDC standards for field encoding and carrier specifications
Keywords: ISO/IEC 20248, DigSig, digital signature, barcode, RFID, AIDC, PKI, offline verification, DigSig Data Description, EncoderGenerator, DecoderVerifier.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 31 - Automatic identification and data capture techniques
- SKU
- ISO/IEC 20248:2022
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 9594-8:2020/Cor 2:2024
ДействующийInformation technology — Open systems interconnection — Part 8: The Directory: Public-key and attribute certi…
Overview ISO/IEC 9594-8:2020/Cor 2:2024 is a technical corrigendum to the international standard for Information Technology-Open Systems Interconnection (OSI)-The Directory: Public-key and Attribute…
ISO/IEC 20248:2022/Amd 1:2024
ДействующийInformation technology — Automatic identification and data capture techniques — Digital signature data struct…
Overview ISO/IEC 20248:2022/Amd 1:2024 is an important amendment to the international standard for information technology related to automatic identification and data capture techniques. This update…