BS ISO/IEC 11770-7:2021
$167.15
Information security. Key management – Cross-domain password-based authenticated key exchange
Published By | Publication Date | Number of Pages |
BSI | 2021 | 36 |
This document specifies mechanisms for cross-domain password-based authenticated key exchange, all of which are four-party password-based authenticated key exchange (4PAKE) protocols. Such protocols let two communicating entities establish a shared session key using just the login passwords that they share with their respective domain authentication servers. The authentication servers, assumed to be part of a standard public key infrastructure (PKI), act as ephemeral certification authorities (CAs) that certify key materials that the users can subsequently use to exchange and agree on as a session key.
This document does not specify the means to be used to establish a shared password between an entity and its corresponding domain server. This document also does not define the implementation of a PKI and the means for two distinct domain servers to exchange or verify their respective public key certificates.
PDF Catalog
PDF Pages | PDF Title |
---|---|
2 | undefined |
6 | Foreword |
7 | Introduction |
9 | 1 Scope 2 Normative references 3 Terms and definitions |
11 | 4 Symbols and abbreviated terms 4.1 Abbreviated terms |
12 | 4.2 Symbols |
14 | 5 Requirements 6 Mechanisms 6.1 General |
15 | 6.2 Sub-protocols and functions 6.2.1 General 6.2.2 Two-party password-based authenticated key exchange |
16 | 6.2.3 Two-party asymmetric-key authenticated key exchange |
17 | 6.2.4 Two-party symmetric-key authenticated key exchange |
18 | 6.2.5 Two-party non-interactive key exchange 6.2.6 Session identity function |
19 | 6.3 Mechanism 1 6.3.1 General 6.3.2 Prior shared parameters 6.3.3 Key exchange operation |
22 | 6.4 Mechanism 2 6.4.1 General 6.4.2 Prior shared parameters |
23 | 6.4.3 Key exchange operation |
25 | 6.5 Mechanism 3 6.5.1 General |
26 | 6.5.2 Prior shared parameters 6.5.3 Key exchange operation |
30 | Annex A (normative) Object identifiers |
31 | Annex B (normative) Conversion functions |
34 | Bibliography |