Information technology — Security techniques — Entity authentication — Part 4: Mechanisms using a cryptographic check function — Technical Corrigendum 2

Technologies de l'information — Techniques de sécurité — Authentification d'entité — Partie 4: Mécanismes utilisant une fonction cryptographique de vérification — Rectificatif technique 2

General Information

Status
Published
Publication Date
12-Jul-2012
Current Stage
6060 - International Standard published
Start Date
13-Jul-2012
Due Date
12-Dec-2014
Completion Date
12-Dec-2014

Relations

Effective Date
26-Nov-2021

Overview

ISO/IEC 9798-4:1999/Cor 2:2012 is a technical corrigendum issued by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) to update Part 4 of ISO/IEC 9798. This part focuses on entity authentication mechanisms using cryptographic check functions, essential for securing identity verification in information technology systems. The corrigendum provides critical clarifications and additions to ensure the robust and standardized application of cryptographic authentication techniques.

This update emphasizes secure practices for the use of secret authentication keys and the uniqueness of cryptographic check values, thereby enhancing the integrity and reliability of authentication processes.

Key Topics

  • Entity Authentication Using Cryptographic Check Functions
    Defines methods for verifying the identity of entities (users, devices, or processes) using cryptographic functions designed to check authenticity.

  • Secret Authentication Key Management
    Specifies that the secret keys used for authentication must be distinct and never reused for other cryptographic purposes to mitigate security risks.

  • Non-Interchangeable Cryptographic Check Values
    Clarifies that cryptographic check values should be uniquely tied to each authentication mechanism and position, preventing their misuse or substitution.

  • Object Identifiers (OIDs)
    Introduces a normative Annex B that defines the object identifiers representing different authentication mechanisms. This supports standardized identification and processing of authentication protocols in implementations.

  • Authentication Mechanism Types Covered

    • Unilateral One-Pass and Two-Pass Authentication
    • Mutual Two-Pass and Three-Pass Authentication Procedures

Applications

  • Secure Entity Verification
    ISO/IEC 9798-4 mechanisms are widely used in systems requiring rigorous identity validation, such as financial services, government digital identities, and secure access control.

  • Cryptographic Protocol Design
    The standard guides developers implementing cryptographic protocols ensuring that keys and authentication values are properly managed and uniquely identified.

  • Interoperability in Security Systems
    Defined object identifiers facilitate interoperability between different security products and applications by providing common references for authentication methods.

  • Network and Information Security
    Applicable to securing client-server communications, virtual private networks (VPNs), and other environments where mutual or unilateral entity authentication is critical.

Related Standards

  • ISO/IEC 9798 Series
    This corrigendum pertains specifically to Part 4 of the ISO/IEC 9798 standard series on entity authentication, which includes other parts addressing various authentication mechanisms such as symmetric, asymmetric, and biometric methods.

  • ISO/IEC 27000 Series
    Complements general information security management standards that include authentication as a core control.

  • ITU-T X.509
    Often used alongside entity authentication standards, especially for digital certificate-based authentication.

  • FIPS 196
    Covers entity authentication using entity authentication protocols, which align with ISO/IEC 9798 methodologies.

Summary

ISO/IEC 9798-4:1999/Cor 2:2012 enhances the security framework for cryptographic entity authentication by enforcing strict key usage and verifying cryptographic check values through defined object identifiers. It plays a pivotal role in standardizing secure authentication mechanisms, thus strengthening trust in global information technology systems. Implementers and security professionals rely on these guidelines to develop interoperable, reliable, and secure identity verification processes.

Buy Documents

Get Certified

Connect with accredited certification bodies for this standard

BSI Group

BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

UKAS United Kingdom Verified

Bureau Veritas

Bureau Veritas is a world leader in laboratory testing, inspection and certification services.

COFRAC France Verified

DNV

DNV is an independent assurance and risk management provider.

NA Norway Verified

Sponsored listings

Frequently Asked Questions

ISO/IEC 9798-4:1999/Cor 2:2012 is a standard published by the International Organization for Standardization (ISO). Its full title is "Information technology — Security techniques — Entity authentication — Part 4: Mechanisms using a cryptographic check function — Technical Corrigendum 2". This standard covers: Information technology — Security techniques — Entity authentication — Part 4: Mechanisms using a cryptographic check function — Technical Corrigendum 2

Information technology — Security techniques — Entity authentication — Part 4: Mechanisms using a cryptographic check function — Technical Corrigendum 2

ISO/IEC 9798-4:1999/Cor 2:2012 is classified under the following ICS (International Classification for Standards) categories: 35.030 - IT Security; 35.040 - Information coding. The ICS classification helps identify the subject area and facilitates finding related standards.

ISO/IEC 9798-4:1999/Cor 2:2012 has the following relationships with other standards: It is inter standard links to ISO/IEC 9798-4:1999. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.

ISO/IEC 9798-4:1999/Cor 2:2012 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


INTERNATIONAL STANDARD ISO/IEC 9798-4:1999
TECHNICAL CORRIGENDUM 2
Published 2012-07-15
INTERNATIONAL ORGANIZATION FOR STANDARDIZATION  МЕЖДУНАРОДНАЯ ОРГАНИЗАЦИЯ ПО СТАНДАРТИЗАЦИИ  ORGANISATION INTERNATIONALE DE NORMALISATION
INTERNATIONAL ELECTROTECHNICAL COMMISSION  МЕЖДУНАРОДНАЯ ЭЛЕКТРОТЕХНИЧЕСКАЯ КОМИССИЯ  COMMISSION ÉLECTROTECHNIQUE INTERNATIONALE

Information technology — Security techniques — Entity
authentication —
Part 4:
Mechanisms using a cryptographic check function
TECHNICAL CORRIGENDUM 2
Technologies de l'information — Techniques de sécurité — Authentification d'entité —
Partie 4: Mécanismes utilisant une fonction cryptographique de vérification
RECTIFICATIF TECHNIQUE 2
Technical Corrigendum 2 to ISO/IEC 9798-4:1999 was prepared by Joint Technical Committee ISO/IEC
JTC 1, Information technology, Subcommittee SC 27, IT Security techniques.

Page iv, Foreword
Add the following text at the end of Foreword:
Annex B of this part of ISO/IEC 9798 is normative, and defines object identifiers.

ICS 35.040 Ref. No. ISO/IEC 9798-4:1999/Cor.2:2012(E)
©  ISO/IEC 2012 – All rights reserved
Published in Switzerland
ISO/IEC 9798-4:1999/Cor.2:2012(E)
Page 2, Clause 4
Add the following text at the end of Clause 4:
d) The secret authentication key used in implementations of any of the mechanisms specified in this part of
ISO/IEC 9798 shall be distinct from the keys used for any other purposes.
e) The cryptographic check values used at various places in an authentication mechanism shall not be
interchangeable.
NOTE This could be enforced by including the following elements in the data s
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.

Loading comments...