Overview - ISO/IEC 13888-3:2020 (Non-repudiation using asymmetric techniques)
ISO/IEC 13888-3:2020 specifies mechanisms for providing communication-related non-repudiation services using asymmetric cryptography. It defines how to create, collect and validate evidence (non‑repudiation tokens) for four specific services: non‑repudiation of origin, delivery, submission, and transport. The standard explains token structure, signature use, time assurances and the role of trusted third parties (TTPs) to support dispute resolution and legal evidentiary requirements.
Key topics and technical requirements
- Non‑repudiation tokens: Mechanisms use digital signatures plus additional data to form tokens (e.g., NROT, NRDT, NRST, NRTT) that are stored as evidence.
- Digital signatures: Tokens must be created with certificate‑based digital signatures. Identity‑based signatures are not permitted. Signature schemes shall conform to ISO/IEC 9796, ISO/IEC 14888 or ISO/IEC 29192‑4.
- Public key certificates: Public verification keys must be bound by certificates that indicate revocation handling periods; verifiability during and after certificate validity is required.
- Time assurance: To prove a token was signed before a given time, the standard requires use of a time‑stamping service or a time‑marking service (see Clause 11).
- Trusted third parties (TTPs): Roles include delivery authorities, time‑stamping/time‑marking authorities, evidence recording authorities and certificate authorities. Entities must trust any TTPs involved.
- Security and policy requirements:
- Signature keys must be kept secret.
- A collision‑resistant hash or identity function must be supported to obtain data imprints.
- Evidence generation/verification mechanisms must satisfy the applicable non‑repudiation policy and be agreed upon prior to evidence generation.
- The standard requires certificate‑based mechanisms and specifies when TTP involvement is needed.
Practical applications
ISO/IEC 13888-3 is applicable to systems where provable communications and dispute-ready evidence are required:
- Secure email and message delivery platforms requiring provable origin/delivery.
- Electronic transaction systems, legal document exchange and e‑procurement where signed evidence is needed.
- Messaging gateways and delivery authorities that must issue submission/transport tokens.
- Organizations designing non‑repudiation services tied to regulatory or contractual evidence requirements.
Who should use this standard
- Security architects, PKI implementers and system integrators
- Messaging and secure communications product teams
- Legal/compliance teams designing evidentiary policies
- Trusted third party operators (time‑stamping, delivery authorities, evidence recorders)
Related standards
Keywords: ISO/IEC 13888-3:2020, non‑repudiation, asymmetric techniques, digital signatures, time‑stamping, delivery authority, non‑repudiation tokens, PKI.