Overview - ISO/IEC 11586-1:1996 (Generic Upper Layers Security, OSI)
ISO/IEC 11586-1:1996 (also published as ITU‑T Recommendation X.830) defines generic models, notations and descriptive tools to support the construction of security-related functions for Open Systems Interconnection (OSI) Upper Layers. It is Part 1 of a multi‑part series (Parts 2–6 address SESE service/protocol, protecting transfer syntax, and PICS proformas). This part focuses on overview, models and notation rather than on concrete cryptographic mechanisms.
Key takeaways:
- Provides formal models for security exchanges, security transformations and protection mappings.
- Supplies notational tools (including ASN.1 guidance) to specify selective field protection and protecting transfer syntaxes.
- Offers informative annexes with examples, guidelines, ASN.1 definitions and relationships to related standards.
Key topics and technical requirements
- Security exchange model and notation: conceptual model for how entities exchange security information (security exchanges, security exchange items, security exchange functions).
- Security transformation model: abstract description of transformations (e.g., protection of presentation data values) that produce protected encodings.
- Protecting transfer syntax and selective field protection: notation and abstract syntax to indicate which fields within an abstract syntax are to be protected.
- Protection mapping: how protection requirements named in an abstract syntax map to specific security transformations.
- Presentation-context-bound, single-item-bound and externally-established security associations: definitions and use cases for association scoping.
- ASN.1 support and encoding rules: Annex A and references to ASN.1 (X.680–X.683, X.690) for specifying abstract syntaxes and initial encodings.
- Conformance and registration: guidance on PICS proformas, object identifier usage and registration of security exchanges/transformations.
- Informative guidance and examples: annexes G–I provide application guidelines and usage examples.
Practical applications - who uses ISO/IEC 11586-1
This standard is useful for:
- Protocol designers and standards authors who need a consistent way to specify security services within OSI Application and Presentation Layer specifications.
- Security architects defining selective field protection, security associations and transformation mappings.
- Implementers of ASEs (Application-Service-Elements) such as SESE (Security Exchange Service Element) and protecting transfer syntax implementations.
- Conformance testers preparing PICS/PIGS proformas and registering security exchanges/transformations.
Related standards and keywords
Related standards include ITU‑T X.830, X.803 (Upper Layers Security Model), ASN.1 (X.680–X.690), X.200 / ISO/IEC 7498‑1 (OSI Basic Reference Model), and other OSI security frameworks. Keywords: ISO/IEC 11586-1, Generic Upper Layers Security, OSI security, security exchanges, security transformations, protecting transfer syntax, ASN.1, selective field protection, SESE, protection mapping.