Overview
ISO 9735-5:2002 defines application-level syntax rules for securing batch EDIFACT (Electronic Data Interchange for Administration, Commerce and Transport) with a focus on authenticity, integrity and non‑repudiation of origin. It specifies how to include EDIFACT security header and trailer segment groups around messages, packages, groups and interchanges so that established security mechanisms can be applied consistently in a batch EDI environment.
Key topics and requirements
- Scope and conformance
- Applies to batch EDI; confidentiality is handled in ISO 9735‑7.
- Uses syntax version number 4 and syntax release 01 (data elements 0002 and 0076 in UNB).
- Conformance implies also complying with ISO 9735 parts 1, 2, 8 and 10.
- Security levels supported
- Message/package level, group level and interchange level security for authenticity, integrity and non‑repudiation.
- Placement and structure
- Security header/trailer groups are inserted after UNH and before UNT for messages, or after UNO and before UNP for packages.
- Defined segments and segment groups include USH (Security Header), USA (Security Algorithm), USC (Certificate), USR (Security Result) and UST (Security Trailer).
- Algorithm and key handling
- Supports symmetric algorithms, hash functions, compression and digital‑signature style mechanisms (message‑dependent hash).
- USH and USA segments convey algorithm identifiers, parameters and optional filter functions; USC carries certificates where asymmetric methods are used.
- Supporting material
- Informative annexes provide threats and solutions, protection examples, filter functions for character repertoires and lists of security services/algorithms.
- Normative references
- Cross‑references to ISO 9735 parts and to ISO/IEC 10181 security frameworks (authentication, integrity, non‑repudiation).
Practical applications
- Implementing tamper‑evident batch EDI exchanges between trading partners (banks, logistics providers, manufacturers, government agencies).
- Enabling non‑repudiation of origin and message integrity in automated B2B workflows.
- Integrating certificate-based or symmetric security mechanisms into existing EDIFACT message flows without changing message content.
Who should use this standard
- EDI implementers, system integrators and software vendors building EDIFACT batch processing solutions.
- Security architects and compliance officers defining EDI security policies.
- Trading partner technical teams needing interoperable message/package-level security in EDIFACT exchanges.
Related standards
- ISO 9735 (other parts: Part 1, 2, 6, 7, 8, 10)
- ISO/IEC 10181‑2, ‑4, ‑6 (authentication, non‑repudiation, integrity frameworks)
Keywords: ISO 9735-5, EDIFACT security, batch EDI, authenticity, integrity, non-repudiation, USH, USA, USC, UST, UNH, UNO.