Overview
ISO/IEC 10736:1995 specifies a Transport Layer Security Protocol (TLSP) for information technology and telecommunications. The standard defines the protocol mechanics for securing Transport Protocol Data Units (TPDUs), establishing Security Associations (SAs), and performing authentication and key distribution using a public‑key based algorithm. It does not define higher‑level management functions or supporting management protocols.
Key topics and technical requirements
- Security Association establishment (SA, SA-P): Protocol elements for creating, negotiating and managing SAs used to protect transport connections.
- Authentication & key distribution: Specifies one public‑key‑based algorithm for authentication and key exchange (document does not name other algorithms).
- Security encapsulation of TPDUs: Structure and encoding of security encapsulation TPDUs, including clear header, crypto sync, protected contents, integrity PAD and ICV fields.
- Confidentiality and integrity services: Procedures for data encipherment, integrity processing (Integrity Check Value - ICV), direction indicator and sequence number processing to protect against replay and tampering.
- Support for connection‑oriented and connectionless transport: Defines security services for both transport types and related SA attributes.
- Security label, padding and peer checks: Label handling, security padding, and peer address verification are specified to ensure correct protection context.
- SA‑Protocol using Key Token Exchange (KTE) and digital signatures: Annex B describes KTE, SA‑protocol authentication, attribute negotiation, rekeying and mapping of SA‑protocol functions to exchanges.
- Conformance & testing: Includes Protocol Implementation Conformance Statement (PICS) proforma and static/dynamic conformance requirements (references to ITU‑T X.224 / ISO/IEC 8073 and X.234 / ISO 8602).
Practical applications - who uses this standard
- Protocol implementers building TLSP support for OSI/TP-based transport stacks or legacy telecom systems.
- Network equipment vendors integrating transport‑layer security features into routers, switches, or specialized gateways.
- Security architects specifying end‑to‑end transport protection for enterprise or industrial networks where OSI transport is used.
- Standards bodies and testers creating conformance test suites and PICS for product certification.
Related standards
- ITU‑T Recommendations and ISO/IEC transport standards referenced for conformance: ITU‑T X.224 / ISO/IEC 8073 (transport protocols), ITU‑T X.234 / ISO 8602.
- ISO/IEC 10736 complements broader security frameworks by focusing specifically on transport‑layer security, SA establishment, and public‑key-based key distribution.
Keywords: ISO/IEC 10736:1995, Transport Layer Security Protocol, Security Association, public key key distribution, TPDU security, integrity, encipherment, KTE, PICS, SA negotiation.