Overview
ISO/IEC 23264-1:2021 - Information security - Redaction of authentic data - Part 1: General - specifies the foundations for cryptographic mechanisms that enable redaction of authenticated data. The standard defines the actors, processes and core cryptographic properties needed so that parts of a previously attested (signed) message can be irreversibly removed while preserving verifiable authenticity for the remaining content. It establishes terminology and a general model to support later parts that may address concrete formats (text, images, video).
Key topics and requirements
- Processes and parties
- Defines the main processes: key generation, redactable attestation, redaction, and verification.
- Identifies participating roles: attestor (creates attestations and specifies which fields may be redacted), redactor (applies redaction using a redaction key), and verifier (checks authenticity of a redacted message).
- Data model
- Describes message decomposition into fields, the notion of admissible changes, attested message, redacted message, and redacted attestation.
- Cryptographic properties
- Required properties: correctness, unforgeability, and privacy (ensuring integrity and controlled disclosure).
- Optional properties: undetectability/detectability of redactions, unlinkability of redactions, disclosure control, consecutive redaction control, and mergeability.
- Redaction key
- Specifies the role of a redaction key (public or private depending on instantiation) that lets redactors apply permitted redactions without revealing the attestor’s private key.
- Scope and constraints
- Limits modifications considered to the irreversible removal of fields (redaction) and sets out how admissible changes are represented and enforced.
Applications
ISO/IEC 23264-1:2021 is aimed at systems that require both authenticity and selective disclosure:
- Privacy-preserving data sharing - share only necessary fields of an attested record while keeping verifiable origin and integrity.
- Selective authentication - prove attributes of a credential without exposing full data.
- Regulated document workflows - government, legal and healthcare records where parts of documents must be redacted yet remain verifiable.
- Audit and compliance - produce redacted evidence that preserves attestation guarantees.
Who should use this standard
- Cryptographers and protocol designers implementing redactable attestation schemes
- Security architects and developers building privacy-preserving data-sharing platforms
- Standards bodies, auditors and organizations managing sensitive digital records
- Implementers of digital signature and attestation solutions seeking interoperability
Related standards
Keywords: ISO/IEC 23264-1:2021, redactable attestation, redaction key, information security, cryptographic redaction, data integrity, privacy-preserving data sharing.