ISO/IEC 11770-4-2006 信息技术.安全技术.密钥管理.第4部分:基于弱机密的机制

作者:标准资料网 时间:2024-05-20 22:48:40   浏览:8585   来源:标准资料网
下载地址: 点击此处下载
【英文标准名称】:Informationtechnology-Securitytechniques-Keymanagement-Part4:Mechanismsbasedonweaksecrets
【原文标准名称】:信息技术.安全技术.密钥管理.第4部分:基于弱机密的机制
【标准号】:ISO/IEC11770-4-2006
【标准状态】:现行
【国别】:国际
【发布日期】:2006-05
【实施或试行日期】:
【发布单位】:国际标准化组织(IX-ISO)
【起草单位】:ISO/IECJTC1/SC27
【标准类型】:()
【标准水平】:()
【中文主题词】:通路;算法;校验;代号系统;编码;用密码写的;数据处理;数据保护;数据安全;数据传输;定义;信息交换;信息技术;口令;资料保护;安全工程
【英文主题词】:Access;Algorithms;Authentication;Codesystems;Coding;Cryptographic;Dataprocessing;Dataprotection;Datasecurity;Datatransmission;Definition;Definitions;Informationinterchange;Informationtechnology;Passwords;Protectionofinformation;Safetyengineering
【摘要】:ThispartofISO/IEC11770defineskeyestablishmentmechanismsbasedonweaksecrets,i.e.,secretsthatcanbereadilymemorizedbyahuman,andhencesecretsthatwillbechosenfromarelativelysmallsetofpossibilities.Itspecifiescryptographictechniquesspecificallydesignedtoestablishoneormoresecretkeysbasedonaweaksecretderivedfromamemorizedpassword,whilepreventingoff-linebrute-forceattacksassociatedwiththeweaksecret.Morespecifically,thesemechanismsaredesignedtoachieveoneofthefollowingthreegoals.1)Balancedpassword-authenticatedkeyagreement:Establishoneormoresharedsecretkeysbetweentwoentitiesthatshareacommonweaksecret.Inabalancedpassword-authenticatedkeyagreementmechanism,thesharedsecretkeysaretheresultofadataexchangebetweenthetwoentities,thesharedsecretkeysareestablishedifandonlyifthetwoentitieshaveusedthesameweaksecret,andneitherofthetwoentitiescanpredeterminethevaluesofthesharedsecretkeys.2)Augmentedpassword-authenticatedkeyagreement:EstablishoneormoresharedsecretkeysbetweentwoentitiesAandB,whereAhasaweaksecretand6hasverificationdataderivedfromaone-wayfunctionofA'sweaksecret.Inanaugmentedpassword-authenticatedkeyagreementmechanism,thesharedsecretkeysaretheresultofadataexchangebetweenthetwoentities,thesharedsecretkeysareestablishedifandonlyifthetwoentitieshaveusedtheweaksecretandthecorrespondingverificationdata,andneitherofthetwoentitiescanpredeterminethevaluesofthesharedsecretkeys.NOTE-ThistypeofkeyagreementmechanismisunabletoprotectA'sweaksecretbeingdiscoveredby6,butonlyincreasesthecostforanadversarytogetA'sweaksecretfrom6.Thereforeitisnormallyusedbetweenaclient(A)andaserver(6).3)Password-authenticatedkeyretrieval:Establishoneormoresecretkeysforanentity,A,associatedwithanotherentity,6,whereAhasaweaksecretandBhasastrongsecretassociatedwithA'sweaksecret.Inanauthenticatedkeyretrievalmechanism,thesecretkeys,retrievablebyA(notnecessarilyderivableby6),aretheresultofadataexchangebetweenthetwoentities,andthesecretkeysareestablishedifandonlyifthetwoentitieshaveusedtheweaksecretandtheassociatedstrongsecret.However,althoughB'sstrongsecretisassociatedwithA'sweaksecret,thestrongsecretdoesnot(initself)containsufficientinformationtopermiteithertheweaksecretorthesecretkeysestablishedinthemechanismtobedetermined.NOTE-ThistypeofkeyretrievalmechanismisusedinthoseapplicationswhereAdoesnothavesecurestorageforastrongsecret,andrequiresB'sassistancetoretrievethestrongsecretforher.Itisnormallyusedbetweenaclient(A)andaserver(6).ThispartofISO/IEC11770doesnotcoveraspectsofkeymanagementsuchas—lifecyclemanagementofweaksecrets,strongsecretsandestablishedsecretkeys;—mechanismstostore,archive,delete,destroy,etc.weaksecrets,strongsecrets,andestablishedsecretkeys.NOTE-Thekeysgeneratedorretrievedthroughtheuseofweaksecretscannotbemoresecureagainstexhaustionthanthesumoftheweaksecretsthemselves.Withthisproviso,themechanismsspecifiedinthispartofISO/IEC11770arerecommendedforpracticaluseinlow-securityenvironments.
【中国标准分类号】:L04
【国际标准分类号】:35_040
【页数】:33P;A4
【正文语种】:英语


下载地址: 点击此处下载
【英文标准名称】:Draughtingmediafortechnicaldrawings;naturaltracingpaper;identicalwithISO9961:1992
【原文标准名称】:技术绘图用制图媒介.天然描图纸
【标准号】:DINISO9961-1994
【标准状态】:现行
【国别】:德国
【发布日期】:1994-03
【实施或试行日期】:
【发布单位】:德国标准化学会(DE-DIN)
【起草单位】:
【标准类型】:()
【标准水平】:()
【中文主题词】:延伸;图纸;规范;定义;作标记;公差(测量);测量;试验;规范(验收);加标签;透明度;绘图室设备;包装;尺寸;描图纸;制图纸;绘图器材;工程图;纸;平滑度(表面);储存
【英文主题词】:Definition;Definitions;Dimensions;Draughtingmedia;Drawingofficeequipment;Drawingpaper;Drawings;Elongation;Engineeringdrawings;Labelling;Labelling(process);Marking;Measurement;Packaging;Paper;Smoothness(surface);Specification(approval);Specifications;Storage;Testing;Tests;Tolerances(measurement);Tracingpaper;Transparency
【摘要】:
【中国标准分类号】:J04
【国际标准分类号】:01_100_40;85_080_10
【页数】:9P.;A4
【正文语种】:德语


【英文标准名称】:MACHINESFORTHESECONDUSEINBUILDINGWORK.CUTTING-OFFMACHINESFORSTONESORSIMILARWITHDIAMONDORABRASIVEWHEELSWITHMANUALADVANCE.SAFETYGENERALRULES.
【原文标准名称】:房屋装修用机械.建筑材料切割用机械.一般安全规则
【标准号】:NFE65-402-1990
【标准状态】:作废
【国别】:法国
【发布日期】:1990-11
【实施或试行日期】:1990-10-20
【发布单位】:法国标准化协会(AFNOR)
【起草单位】:
【标准类型】:()
【标准水平】:()
【中文主题词】:
【英文主题词】:
【摘要】:
【中国标准分类号】:P97
【国际标准分类号】:25_080_60;91_220
【页数】:15P;A4
【正文语种】:其他