Overview
ISO/IEC 11586-3:1996 - Information technology - Open Systems Interconnection - Generic upper layers security: Security Exchange Service Element (SESE) protocol specification - defines the protocol-level behaviour for an Application Service Element (ASE) that conveys security information between application-layer peers. Part 3 of the ISO/IEC 11586 series is identical to ITU‑T Rec. X.832 and specifies the APDUs, procedures, ASN.1 encoding approach and mappings needed to implement SESE in OSI-based systems.
Key topics and technical requirements
- Scope and purpose
- Provides generic facilities to support security services in application-layer protocols (selective field protection, security exchanges, transformations).
- Protocol elements
- Defines SESE APDUs: SE-TRANSFER (SETR), SE-U-ABORT (SEAB), SE-P-ABORT (SEPA).
- Describes transfer, user-initiated abort and provider-initiated abort procedures.
- Encoding and syntax
- APDUs are parameterized using ASN.1 (referenced X.680–X.683 family) and encoded according to BER/CER/DER rules (X.690).
- Clause 7 describes generic APDU specification and abstract syntax construction for tailored SESE definitions.
- Mapping and integration
- Mappings to Presentation Layer services and ACSE (Association Control Service Element) are defined to allow APDUs to be transported or embedded within ASO/application PDUs.
- Error handling and problem codes
- Categorizes problems: general, transfer, abort, with examples such as Invalid APDU, Duplicate invocation identifier, Unrecognized security exchange, Mistyped item.
- Conformance
- Includes conformance requirements, PICS proforma (covered by other parts of the series), and SEPM (Security Exchange Protocol Machine) state behaviour (Annex A).
Applications and target users
- Who uses it:
- Protocol designers and developers implementing application-layer security in OSI-compliant systems.
- Security architects specifying secure application protocols that require exchange of cryptographic material, tokens or policy information.
- Vendors producing middleware, secure application-service-elements, or conformance test suites for SESE.
- Practical uses:
- Structuring and encoding security exchanges (e.g., key or token exchange metadata) between application peers.
- Defining interoperable abort and error semantics for security negotiations.
- Integrating security exchange functionality into existing ACSE/Presentation mappings for OSI-based distributed applications.
Related standards
- ISO/IEC 11586 series (Parts 1–6), especially:
- Part 1: Overview, models and notation
- Part 2: SESE service definition
- Part 4: Protecting transfer syntax
- Parts 5–6: PICS proforma
- ITU‑T Recommendations: X.832 (identical text), X.803 (upper layers security model), ACSE and ASN.1 (X.217, X.226, X.227, X.680–X.690).
Keywords: ISO/IEC 11586-3:1996, SESE, Security Exchange Service Element, SE-TRANSFER, ASN.1, APDU, OSI application layer security, ITU‑T X.832, ACSE, SEPM.