ISO/IEC 9798-5:2009 PDF
Information technology — Security techniques — Entity authentication — Part 5: Mechanisms using zero-knowledge techniques
Information technology — Security techniques — Entity authentication — Part 5: Mechanisms using zero-knowledge techniques
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 53
- Дата публикации:
- 11 декабря 2009 г.
- Издание:
- ISO/IEC IS 9798 edition 3 version 1
- ICS:
- 35.030
ISO/IEC 9798-5:2009 specifies entity authentication mechanisms using zero-knowledge techniques: mechanisms based on identities and providing unilateral authentication; mechanisms based on integer factorization and providing unilateral authentication; mechanisms based on discrete logarithms with respect to numbers that are either prime or composite, and providing unilateral authentication; mechanisms based on asymmetric encryption systems and providing either unilateral authentication, or mutual authentication; mechanisms based on discrete logarithms on elliptic curves and providing unilateral authentication. These mechanisms are constructed using the principles of zero-knowledge techniques, but they are not necessarily zero-knowledge according to the strict definition for every choice of parameters.
Abstract
Overview
ISO/IEC 9798-5:2009 - part of the ISO/IEC 9798 series - specifies entity authentication mechanisms using zero-knowledge techniques. Published as the third edition in 2009, it defines a family of authentication exchanges between a claimant and a verifier built on zero-knowledge principles. The standard covers mechanisms based on identities, integer factorization, discrete logarithms (prime and composite moduli), asymmetric encryption systems (supporting unilateral or mutual authentication), and elliptic-curve discrete logarithms. It also provides normative and informative annexes with object identifiers, zero-knowledge principles, parameter guidance, and numerical examples.
Key topics and technical requirements
- Mechanism families: identity-based, integer-factorization-based, discrete-logarithm-based (prime/composite), asymmetric-encryption-based (unilateral/mutual), and elliptic-curve discrete logarithm mechanisms.
- Authentication flows: definitions and formats for witness, challenge, response, and the exchange multiplicity of messages in an authentication instance.
- Key production and management: procedures and requirements for generating private/public keys, accreditation exponents, adaptation parameters, and domain parameters.
- Security environment requirements: prerequisites for safe deployment of each mechanism family (e.g., randomness, parameter selection, and computational assumptions).
- Operational concepts: unilateral vs mutual authentication, coupon strategy (pre-computation to reduce runtime work for constrained claimants or verifiers), and token/claimant parameter handling.
- Parameter guidance: Annex C provides guidance on choosing parameters and comparing mechanisms; Annex D includes numerical examples to aid implementation.
- Terminology: clear definitions of claimant, verifier, private/public key, secret/response, token, and other cryptographic terms used in entity authentication.
- Caveat: mechanisms follow zero-knowledge principles but “may not be strictly zero-knowledge” for every parameter choice - implementers must heed parameter guidance.
Applications and who uses it
ISO/IEC 9798-5 is targeted at professionals designing and implementing strong authentication for systems that require cryptographic assurance of identity:
- Security architects and protocol designers building authentication schemes
- PKI and certificate authorities integrating authentication primitives
- Cryptographers and researchers comparing zero-knowledge-based schemes
- Embedded and IoT device manufacturers using coupon strategies to offload compute
- Auditors, compliance teams and vendors assessing cryptographic authentication mechanisms
Practical uses include secure login, device pairing, firmware/authentication tokens, challenge–response APIs, and protocols where private keys must be proven without disclosure.
Related standards
- ISO/IEC 9798 (other parts): Part 1 (General), Part 2 (symmetric algorithms), Part 3 (digital signatures), Part 4 (cryptographic check function), Part 6 (manual data transfer).
- Annexes in ISO/IEC 9798-5: principles of zero-knowledge (B), parameter guidance (C), numerical examples (D).
Keywords: ISO/IEC 9798-5:2009, entity authentication, zero-knowledge techniques, discrete logarithm, elliptic curve, integer factorization, asymmetric encryption, authentication mechanisms.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 9798-5:2009
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO/IEC 9798-4:1999/Cor 2:2012
ДействующийInformation technology — Security techniques — Entity authentication — Part 4: Mechanisms using a cryptograph…
Overview ISO/IEC 9798-4:1999/Cor 2:2012 is a technical corrigendum issued by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) to update…
ISO/IEC 9798-5:2004
ОтменёнInformation technology — Security techniques — Entity authentication — Part 5: Mechanisms using zero-knowledg…
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…