您的位置: 标准下载 » 国际标准 » ISO 国际标准 »

ISO/IEC 11770-4-2006 信息技术.安全技术.密钥管理.第4部分:基于弱机密的机制

作者:标准资料网 时间:2024-05-09 20:00:23  浏览:8768   来源:标准资料网
下载地址: 点击此处下载
【英文标准名称】:Informationtechnology-Securitytechniques-Keymanagement-Part4:Mechanismsbasedonweaksecrets
【原文标准名称】:信息技术.安全技术.密钥管理.第4部分:基于弱机密的机制
【标准号】:ISO/IEC11770-4-2006
【标准状态】:现行
【国别】:国际
【发布日期】:2006-05
【实施或试行日期】:
【发布单位】:国际标准化组织(IX-ISO)
【起草单位】:ISO/IECJTC1/SC27
【标准类型】:()
【标准水平】:()
【中文主题词】:通路;算法;校验;代号系统;编码;用密码写的;数据处理;数据保护;数据安全;数据传输;定义;信息交换;信息技术;口令;资料保护;安全工程
【英文主题词】:Access;Algorithms;Authentication;Codesystems;Coding;Cryptographic;Dataprocessing;Dataprotection;Datasecurity;Datatransmission;Definition;Definitions;Informationinterchange;Informationtechnology;Passwords;Protectionofinformation;Safetyengineering
【摘要】:ThispartofISO/IEC11770defineskeyestablishmentmechanismsbasedonweaksecrets,i.e.,secretsthatcanbereadilymemorizedbyahuman,andhencesecretsthatwillbechosenfromarelativelysmallsetofpossibilities.Itspecifiescryptographictechniquesspecificallydesignedtoestablishoneormoresecretkeysbasedonaweaksecretderivedfromamemorizedpassword,whilepreventingoff-linebrute-forceattacksassociatedwiththeweaksecret.Morespecifically,thesemechanismsaredesignedtoachieveoneofthefollowingthreegoals.1)Balancedpassword-authenticatedkeyagreement:Establishoneormoresharedsecretkeysbetweentwoentitiesthatshareacommonweaksecret.Inabalancedpassword-authenticatedkeyagreementmechanism,thesharedsecretkeysaretheresultofadataexchangebetweenthetwoentities,thesharedsecretkeysareestablishedifandonlyifthetwoentitieshaveusedthesameweaksecret,andneitherofthetwoentitiescanpredeterminethevaluesofthesharedsecretkeys.2)Augmentedpassword-authenticatedkeyagreement:EstablishoneormoresharedsecretkeysbetweentwoentitiesAandB,whereAhasaweaksecretand6hasverificationdataderivedfromaone-wayfunctionofA'sweaksecret.Inanaugmentedpassword-authenticatedkeyagreementmechanism,thesharedsecretkeysaretheresultofadataexchangebetweenthetwoentities,thesharedsecretkeysareestablishedifandonlyifthetwoentitieshaveusedtheweaksecretandthecorrespondingverificationdata,andneitherofthetwoentitiescanpredeterminethevaluesofthesharedsecretkeys.NOTE-ThistypeofkeyagreementmechanismisunabletoprotectA'sweaksecretbeingdiscoveredby6,butonlyincreasesthecostforanadversarytogetA'sweaksecretfrom6.Thereforeitisnormallyusedbetweenaclient(A)andaserver(6).3)Password-authenticatedkeyretrieval:Establishoneormoresecretkeysforanentity,A,associatedwithanotherentity,6,whereAhasaweaksecretandBhasastrongsecretassociatedwithA'sweaksecret.Inanauthenticatedkeyretrievalmechanism,thesecretkeys,retrievablebyA(notnecessarilyderivableby6),aretheresultofadataexchangebetweenthetwoentities,andthesecretkeysareestablishedifandonlyifthetwoentitieshaveusedtheweaksecretandtheassociatedstrongsecret.However,althoughB'sstrongsecretisassociatedwithA'sweaksecret,thestrongsecretdoesnot(initself)containsufficientinformationtopermiteithertheweaksecretorthesecretkeysestablishedinthemechanismtobedetermined.NOTE-ThistypeofkeyretrievalmechanismisusedinthoseapplicationswhereAdoesnothavesecurestorageforastrongsecret,andrequiresB'sassistancetoretrievethestrongsecretforher.Itisnormallyusedbetweenaclient(A)andaserver(6).ThispartofISO/IEC11770doesnotcoveraspectsofkeymanagementsuchas—lifecyclemanagementofweaksecrets,strongsecretsandestablishedsecretkeys;—mechanismstostore,archive,delete,destroy,etc.weaksecrets,strongsecrets,andestablishedsecretkeys.NOTE-Thekeysgeneratedorretrievedthroughtheuseofweaksecretscannotbemoresecureagainstexhaustionthanthesumoftheweaksecretsthemselves.Withthisproviso,themechanismsspecifiedinthispartofISO/IEC11770arerecommendedforpracticaluseinlow-securityenvironments.
【中国标准分类号】:L04
【国际标准分类号】:35_040
【页数】:33P;A4
【正文语种】:英语


下载地址: 点击此处下载
【英文标准名称】:TerrestrialTrunkedRadio(TETRA)-VoiceplusData(V+D)-Part10:Supplementaryservicesstage1-Sub-part12:CallHold(HOLD)(EndorsementoftheEnglishversionEN300392-10-12V1.3.1(2004-02)asGermanstandard)
【原文标准名称】:地面中继无线电系统(TETRA).声音加数据(V+D).第10部分:补充业务阶段1.第12分部分:呼叫保持
【标准号】:DINEN300392-10-12-2004
【标准状态】:现行
【国别】:德国
【发布日期】:2004-12
【实施或试行日期】:
【发布单位】:德国标准化学会(DIN)
【起草单位】:
【标准类型】:()
【标准水平】:()
【中文主题词】:电信;无线电广播网;数据传送;TETRA;语音传输;无线通信业务;补充业务;无线电设备;无线电装置;呼叫;通信
【英文主题词】:Calls;Datatransfer;Radioequipment;Radionetworks;Radiosystems;Speechtransmission;Supplementaryservices;Telecommunication;Telecommunications;TETRA;Transeuropeantrunkedradio;Wirelesscommunicati
【摘要】:ThisEuropeanstandardspecifiesrequirementsinthetelecommunicationssector.
【中国标准分类号】:M36
【国际标准分类号】:33_070_10
【页数】:2P;A4
【正文语种】:德语


【英文标准名称】:Basisofdesignandactionsonstructures.Actionsonstructures.Windactions(togetherwithUnitedKingdomNationalApplicationDocument)
【原文标准名称】:结构设计和作用力基础知识.对结构的作用力.风的作用力(结合英国国家应用文件一起使用)
【标准号】:DDENV1991-2-4-1997
【标准状态】:现行
【国别】:英国
【发布日期】:1997-06-15
【实施或试行日期】:1997-06-15
【发布单位】:英国标准学会(BSI)
【起草单位】:BSI
【标准类型】:()
【标准水平】:()
【中文主题词】:负荷;角(几何学);屋顶;桥;道路;铁路设施;地形学;速度;风荷载;形状;结构设计;风;石;地图;空气动力学;气象测量;气象学;铁路;设计;建筑物;结构;高度;气候荷载;钢;人行桥;空气动力学特性;混凝土;墙;压力;烟囱
【英文主题词】:
【摘要】:
【中国标准分类号】:P20
【国际标准分类号】:91_010_30
【页数】:214P;A4
【正文语种】:英语