Overview - ISO/IEC 13888-1:2020 (Non-repudiation, General)
ISO/IEC 13888-1:2020 defines a general model for non-repudiation services in information security. It establishes how evidence is generated, transferred, stored and verified using cryptographic techniques. This part serves as the foundation for subsequent parts of the ISO/IEC 13888 series and focuses on mechanisms-such as digital signatures and secure envelopes-and the roles of trusted third parties (time-stamping authorities, certification authorities, notaries, delivery authorities). Dispute arbitration is explicitly outside the scope.
Keywords: ISO/IEC 13888-1:2020, non-repudiation, information security, digital signatures, secure envelopes, time-stamping.
Key technical topics and requirements
- Phases of non-repudiation covered
- Evidence generation
- Evidence transfer, storage and retrieval
- Evidence verification
- Non-repudiation tokens
- Generic tokens composed of secure envelopes and/or digital signatures
- Specific tokens (time-stamp tokens, notarization tokens) and how they augment evidence
- Cryptographic requirements
- Use of symmetric (MAC/secure envelopes) and asymmetric (digital signatures) techniques
- Hash-functions required to be collision-resistant
- Definition and handling of cryptographic check functions and cryptographic check values
- Entities and roles
- Evidence generator, evidence verifier, evidence requester, evidence subject, delivery authority, certification authority, adjudicator
- Trusted third-party involvement across evidence phases (generation, transfer/storage, verification)
- Document organization & terminology
- Updated terms and definitions, symbols, and abbreviated terms (fourth edition updates include revised Clause 3 and fixed terminology)
Practical applications and who uses this standard
ISO/IEC 13888-1 is practical for organizations building reliable evidence chains in digital transactions and systems where accountability is critical:
- Security architects and PKI implementers designing non-repudiation services
- Software developers and system integrators implementing message-level evidence (signatures, envelopes, timestamps)
- Cloud and message service providers managing evidence storage and retrieval
- Legal, compliance, and audit teams assessing evidentiary strength of digital records
- Trusted third parties (time-stamping authorities, CAs, notaries) aligning services with international models
Related standards
Adopting ISO/IEC 13888-1:2020 helps organizations implement standardized, cryptography-based evidence mechanisms that support accountability and verifiable proof of digital actions and events.