Overview
ISO/IEC 24727-6:2010 specifies procedures for the registration authority (RA) that manages the publication and registration of authentication protocols (APs) used with integrated circuit cards (ICC). The standard enables unambiguous identification of APs (and related cryptographic algorithms, test methods and conformance criteria) so implementers can advertise and achieve interoperability. It defines administrative processes for assigning Object Identifiers (OIDs), maintaining a web-based register, and recording formal adoption of ISO/IEC 24727 APs.
Keywords: ISO/IEC 24727-6:2010, authentication protocols, registration authority, OID, interoperability, integrated circuit cards.
Key Topics
- Scope of registration: registration of new or revised APs, associated cryptographic algorithms, authentication protocol test plans (APTP) and conformance assessment criteria; registration of AP adoption by organizations.
- Registration procedures: application content, RA completeness checks, investigation of doubts, acceptance/rejection, OID allocation and publication.
- OID management: extension of ISO/IEC 24727-3 OID method using an RA arc under ISO/IEC 9834-2 to support extensibility and interoperability.
- Publication model: public, web-based database of registered APs and adopters; support for “Draft Only” and final publication states and procedures for withdrawal or pending de-registration.
- Administrative role of the RA: RA performs administrative checks and OID assignment; it is not responsible for technical validation of the AP content (beyond completeness and conformity with procedural requirements).
- Dependencies: relies on ISO/IEC 24727-3 for AP/algorithm descriptions and ISO/IEC 24727-5 for conformance testing methodology (and ISO/IEC 9834-2 for OID procedures).
Practical Applications
- Provide a central registry for developers and integrators to reference APs and cryptographic profiles when designing ICC-aware systems.
- Allow vendors and community groups to advertise interoperability by registering AP adoption, useful when specifying compatible card readers, middleware or backend services.
- Support conformance and testing organizations by linking registered APs to test plans and assessment criteria.
- Facilitate clearer supply-chain communication in projects that require secure mutual authentication between cards and external applications.
Who Uses This Standard
- Card manufacturers and smart-card OS developers
- System integrators and middleware vendors
- Test laboratories and conformance assessors
- Standards bodies, government agencies and industry consortia specifying interoperable authentication protocols
Related Standards
This part of ISO/IEC 24727 helps organizations manage, reference and adopt authentication protocols consistently - a practical foundation for interoperable ICC authentication deployments.