ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Entity authentication

Similar documents
ISO/IEC INTERNATIONAL STANDARD. Information technology EAN/UCC Application Identifiers and Fact Data Identifiers and Maintenance

This is a preview - click here to buy the full publication GUIDE 51. Safety aspects Guidelines for their inclusion in standards. Second edition 1999

ISO INTERNATIONAL STANDARD. Technical product documentation Lettering Part 4: Diacritical and particular marks for the Latin alphabet

ISO/IEC INTERNATIONAL STANDARD

ISO 3901 INTERNATIONAL STANDARD. Information and documentation International Standard Recording Code (ISRC)

ISO INTERNATIONAL STANDARD. Statistical interpretation of data Part 7: Median Estimation and confidence intervals

ISO/IEC INTERNATIONAL STANDARD. Systems and software engineering Measurement process. Ingénierie des systèmes et du logiciel Processus de mesure

ISO 2944 INTERNATIONAL STANDARD. Fluid power systems and components Nominal pressures. Transmissions hydrauliques et pneumatiques Pressions nominales

ISO/IEC INTERNATIONAL STANDARD. Software engineering Product evaluation Part 3: Process for developers

ISO/IEC INTERNATIONAL STANDARD. Software engineering Software measurement process. Ingénierie du logiciel Méthode de mesure des logiciels

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Key management Part 4: Mechanisms based on weak secrets

ISO 3085 INTERNATIONAL STANDARD. Iron ores Experimental methods for checking the precision of sampling, sample preparation and measurement

ISO 186 INTERNATIONAL STANDARD. Paper and board Sampling to determine average quality

ISO 3871 INTERNATIONAL STANDARD. Road vehicles Labelling of containers for petroleum-based or non-petroleum-based brake fluid

ISO/IEC INTERNATIONAL STANDARD. Information technology MPEG extensible middleware (MXM) Part 3: MXM reference software

INTERNATIONAL STANDARD

ISO INTERNATIONAL STANDARD. Information and documentation International Standard Musical Work Code (ISWC)

ISO INTERNATIONAL STANDARD. Machinery for forestry Wheeled skidders Terms, definitions and commercial specifications

INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Hash-functions Part 2: Hash-functions using an n-bit block cipher

ISO INTERNATIONAL STANDARD. Manipulating industrial robots Mechanical interfaces Part 2: Shafts

INTERNATIONAL STANDARD

ISO INTERNATIONAL STANDARD. Laboratory glassware Bottles Part 2: Conical neck bottles

ISO INTERNATIONAL STANDARD. Condition monitoring and diagnostics of machines General guidelines on using performance parameters

ISO INTERNATIONAL STANDARD. Translation-oriented terminography. Terminographie axée sur la traduction. First edition

ISO 7914 INTERNATIONAL STANDARD. Forestry machinery Portable chainsaws Minimum handle clearance and sizes

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD

INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD

ISO 2535 INTERNATIONAL STANDARD. Plastics Unsaturated-polyester resins Measurement of gel time at ambient temperature

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Modes of operation for an n-bit block cipher

ISO 1009 INTERNATIONAL STANDARD. Photography Paper dimensions Rolls for printers. Photographie Dimensions des papiers Rouleaux pour tireuses

ISO/IEC INTERNATIONAL STANDARD. Information technology Icon symbols and functions for controlling multimedia software applications

ISO/IEC INTERNATIONAL STANDARD. Information technology Guideline for the evaluation and selection of CASE tools

ISO/IEC TR TECHNICAL REPORT. Software engineering Mock up and prototype A categorization of software mock up and prototype models and their use

ISO/IEC INTERNATIONAL STANDARD

ISO 1173 INTERNATIONAL STANDARD

ISO/IEC Information technology Icon symbols and functions for controlling multimedia software applications

ISO 7-2 INTERNATIONAL STANDARD. Pipe threads where pressure-tight joints are made on the threads Part 2: Verification by means of limit gauges

ISO/IEC INTERNATIONAL STANDARD. Colour test pages for measurement of office equipment consumable yield

ISO 4507 INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD. Information technology Message Handling Systems (MHS): MHS routing

ISO INTERNATIONAL STANDARD. Information and documentation Records management Part 1: General

ISO INTERNATIONAL STANDARD. Ophthalmic optics Contact lenses and contact lens care products Fundamental requirements

ISO/IEC INTERNATIONAL STANDARD

ISO INTERNATIONAL STANDARD. Ergonomic design of control centres Part 3: Control room layout

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD. Information technology Keyboard layouts for text and office systems Part 2: Alphanumeric section

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD

ISO INTERNATIONAL STANDARD. Graphical symbols for diagrams Part 8: Valves and dampers

ISO/IEC INTERNATIONAL STANDARD. Information technology Multimedia Middleware Part 6: Fault management

ISO/IEC INTERNATIONAL STANDARD. Identification cards Recording technique Part 6: Magnetic stripe High coercivity

INTERNATIONAL STANDARD

ISO INTERNATIONAL STANDARD. Ergonomic design of control centres Part 2: Principles for the arrangement of control suites

ISO/IEC INTERNATIONAL STANDARD. Information technology Open distributed processing Reference model: Foundations

ISO INTERNATIONAL STANDARD. Lubricants, industrial oils and related products (class L) Classification Part 1: Family A (Total loss systems)

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques IT network security Part 2: Network security architecture

ISO AMENDMENT 1 Ergonomic requirements for office work with visual display terminals (VDTs) General introduction

ISO INTERNATIONAL STANDARD. Graphical symbols for diagrams Part 11: Devices for heat transfer and heat engines

ISO/IEC This is a preview - click here to buy the full publication INTERNATIONAL STANDARD. Second edition

ISO/IEC INTERNATIONAL STANDARD. Information technology CDIF transfer format Part 3: Encoding ENCODING.1

ISO INTERNATIONAL STANDARD. Internal combustion engines Piston rings Part 3: Material specifications

INTERNATIONAL STANDARD. Vanilla [Vanilla fragrans (Salisbury) Ames] Part 1: Specification

ISO/IEC 2593 INTERNATIONAL STANDARD

ISO/IEC TR This is a preview - click here to buy the full publication TECHNICAL REPORT. First edition

ISO/IEC INTERNATIONAL STANDARD. Information technology ASN.1 encoding rules: XML Encoding Rules (XER)

INTERNATIONAL STANDARD

ISO INTERNATIONAL STANDARD

ISO/IEC TR TECHNICAL REPORT

ISO 3523 INTERNATIONAL STANDARD. Oil of cananga [Cananga odorata (Lam.) Hook. f. et Thomson, forma macrophylla]

ISO 2253 INTERNATIONAL STANDARD. Curry powder Specification. Poudre de curry Spécifications. Third edition

ISO/IEC INTERNATIONAL STANDARD

ISO INTERNATIONAL STANDARD

ISO Microbiology of food and animal feeding stuffs Horizontal method for the enumeration of psychrotrophic microorganisms

ISO 105-F07 INTERNATIONAL STANDARD. Textiles Tests for colour fastness Part F07: Specification for secondary acetate adjacent fabric

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security management system implementation guidance

INTERNATIONAL STANDARD

Transcription:

INTERNATIONAL STANDARD ISO/IEC 9798-4 Second edition 1999-12-15 Information technology Security techniques Entity authentication Part 4: Mechanisms using a cryptographic check function Technologies de l information Techniques de sécurité Authentification d'entité Partie 4: Mécanismes utilisant une fonction cryptographique de vérification Reference number ISO/IEC 1999

This is a preview - click here to buy the full publication PDF disclaimer This PDF file may contain embedded typefaces. In accordance with Adobe s licensing policy, this file may be printed or viewed but shall not be edited unless the typefaces which are embedded are licensed to and installed on the computer performing the editing. In downloading this file, parties accept therein the responsibility of not infringing Adobe s licensing policy. The ISO Central Secretariat accepts no liability in this area. Adobe is a trademark of Adobe Systems Incorporated. Details of the software products used to create this PDF file can be found in the General Info relative to the file; the PDF-creation parameters were optimized for printing. Every care has been taken to ensure that the file is suitable for use by ISO member bodies. In the unlikely event that a problem relating to it is found, please inform the Central Secretariat at the address given below. ISO/IEC 1999 All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and microfilm, without permission in writing from either ISO at the address below or ISO's member body in the country of the requester. ISO copyright office Case postale 56 Ÿ CH-1211 Geneva 20 Tel. + 41 22 749 01 11 Fax + 41 22 734 10 79 E-mail copyright@iso.ch Web www.iso.ch Printed in Switzerland ii

Contents 1 Scope... 1 2 Normative references... 1 3 Definitions and notation... 1 4 Requirements... 1 5 Mechanisms... 2 5.1 Unilateral authentication... 2 5.1.1 One pass authentication... 2 5.1.2 Two pass authentication... 3 5.2 Mutual authentication... 4 5.2.1 Two pass authentication... 4 5.2.2 Three pass authentication... 5 Annex A Use of text fields... 7 iii

This is a preview - click here to buy the full publication Foreword ISO (the International Organization for Standardization) and IEC (the International Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established by the respective organization to deal with particular fields of technical activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the work. International Standards are drafted in accordance with the rules given in the ISO/IEC Directives, Part 3. In the field of information technology, ISO and IEC have established a joint technical committee, ISO/IEC JTC 1. Draft International Standards adopted by the joint technical committee are circulated to national bodies for voting. Publication as an International Standard requires approval by at least 75 % of the national bodies casting a vote. Attention is drawn to the possibility that some of the elements of this part of ISO/IEC 9798 may be the subject of patent rights. ISO and IEC shall not be held responsible for identifying any or all such patent rights. International Standard ISO/IEC 9798-4 was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology, Subcommittee SC 27, IT Security techniques. This second edition cancels and replaces the first edition (ISO/IEC 9798-4:1995), which has been technically revised. Note, however, that implementations which comply with ISO/IEC 9798-4 (1st edition) will be compliant with ISO/IEC 9798-4 (2nd edition). ISO/IEC 9798 consists of the following parts, under the general title Information technology Security techniques Entity authentication: Part 1: General Part 2: Mechanisms using symmetric encipherment algorithms Part 3: Mechanisms using digital signature techniques Part 4: Mechanisms using a cryptographic check function Part 5: Mechanisms using zero knowledge techniques Further parts may follow. Annex A of this part of ISO/IEC 9798 is for information only. iv

INTERNATIONAL STANDARD Information technology Security techniques Entity authentication Part 4: Mechanisms using a cryptographic check function 1 Scope This part of ISO/IEC 9798 specifies entity authentication mechanisms using a cryptographic check function. Two mechanisms are concerned with the authentication of a single entity (unilateral authentication), while the remaining are mechanisms for mutual authentication of two entities. The mechanisms specified in this part of ISO/IEC 9798 use time variant parameters such as time stamps, sequence numbers, or random numbers, to prevent valid authentication information from being accepted at a later time or more than once. If a time stamp or sequence number is used, one pass is needed for unilateral authentication, while two passes are needed to achieve mutual authentication. If a challenge and response method employing random numbers is used, two passes are needed for unilateral authentication, while three passes are required to achieve mutual authentication. Examples of cryptographic check functions are given in ISO/IEC 9797. 2 Normative references The following normative documents contain provisions which, through reference in this text, constitute provisions of this part of ISO/IEC 9798. For dated references, subsequent amendments to, or revisions of, any of these publications do not apply. However, parties to agreements based on this part of ISO/IEC 9798 are encouraged to investigate the possibility of applying the most recent editions of the normative documents indicated below. For undated references, the latest edition of the normative document referred to applies. Members of ISO and IEC maintain registers of currently valid International Standards. ISO/IEC 9797 (all parts), Information technology Security techniques Message Authentication Codes (MACs). ISO/IEC 9798-1:1997, Information technology Security techniques Entity authentication Part 1: General. 1