Overview
ISO/IEC 11586-4:1996 - Protecting transfer syntax specification defines a generic protecting transfer syntax for the Presentation Layer to support security services in OSI (Open Systems Interconnection) applications. Identical to ITU‑T Recommendation X.833, this part of the Generic Upper Layers Security (GULS) series specifies how to represent, transfer and negotiate the outputs of security transformations (protected data and associated parameters) for secure application-layer communication.
Key topics and technical requirements
- Protecting transfer syntax concept: a context‑sensitive (stateful) transfer syntax that packages transformed user data, protected static/dynamic parameters and identifiers for security transformations or externally established security associations.
- Security transformation model: maps unprotected ASN.1 abstract-syntax values (or other abstract syntaxes) through an initial encoding and a security transformation to a transfer representation.
- Initial encoding rules: rules used to map an abstract syntax to an unprotected syntax; may be selected via a static parameter or via the transformation’s initialEncodingRules default (e.g., ASN.1 BER/CER/DER variants).
- ASN.1 data structures: defines the SyntaxStructure ASN.1 type (parameterized by a set of SECURITY‑TRANSFORMATION objects, ValidSTs) with variants for first PDV (presentation data value) and subsequent PDVs.
- Negotiation and signaling: use of protecting transfer syntaxes is negotiated through the Presentation protocol or announced using ASN.1 EXTERNAL/EMBEDDED PDV constructs; object identifier assignment is addressed.
- Conformance and PICS proforma: conformance clauses and Protocol Implementation Conformance Statement (PICS) support (see Parts 5–6 of ISO/IEC 11586).
- State and synchronization: retaining state within encoders/decoders and specifying synchronization procedures for protecting presentation contexts.
Applications
- Secure transfer of application-layer data in systems that implement OSI Presentation Layer services.
- Designing and implementing presentation-context-bound, single-item-bound, or externally-established security associations.
- Generating tailored protecting transfer syntaxes by combining the generic syntax with concrete security transformation definitions (e.g., encryption, integrity transformations).
- Interoperability testing and conformance verification for secure messaging and transaction systems that follow OSI security models.
Who should use this standard
- Protocol architects and implementers building OSI-compliant Presentation Layer security.
- Vendors of secure messaging, middleware and gateways that require standardized transfer encodings.
- Security engineers specifying ASN.1-based protected PDVs and security transformations.
- Test labs and compliance teams producing PICS and verifying interoperability.
Related standards
Keywords: ISO/IEC 11586-4:1996, protecting transfer syntax, Open Systems Interconnection, security transformation, ASN.1, presentation layer, transfer syntax, Generic Upper Layers Security (GULS).