CSA - CAN/CSA-ISO/IEC 11770-4:07
Information technology - Security techniques - Key management - Part 4: Mechanisms based on weak secrets
| Organization: | CSA |
| Publication Date: | 1 January 2007 |
| Status: | inactive |
| Page Count: | 56 |
| ICS Code (Information coding): | 35.040 |
scope:
This part of ISO/IEC 11770 defines key establishment mechanisms based on weak secrets, i.e., secrets that can be readily memorized by a human, and hence secrets that will be chosen from a relatively small set of possibilities. It specifies cryptographic techniques specifically designed to establish one or more secret keys based on a weak secret derived from a memorized password, while preventing off-line brute-force attacks associated with the weak secret. More specifically, these mechanisms are designed to achieve one of the following three goals.
1) Balanced password-authenticat
2) Augmented password-authenticat
NOTE This type of key agreement mechanism is unable to protect A's weak secret being discovered by B, but only increases the cost for an adversary to get A's weak secret from B. A typical application scenario would involve use between a client (A) and a server (B).
3) Password-authenticat
NOTE This type of key retrieval mechanism is used in those applications where A does not have secure storage for a strong secret, and requires B's assistance to retrieve the strong secret. Such a mechanism is appropriate for use between a client (A) and a server (B).
This part of ISO/IEC 11770 does not cover the following aspects of key management.
- lifecycle management of weak secrets, strong secrets and established secret keys;
- mechanisms to store, archive, delete, destroy, etc. weak secrets, strong secrets, and established secret keys.
NOTE - The keys generated or retrieved through the use of weak secrets cannot be more secure against exhaustion than the sum of the weak secrets themselves. With this proviso, the mechanisms specified in this part of ISO/IEC 11770 are recommended for practical use in low-security environments.
Document History