Overview
ISO/IEC 18033-5:2015/Amd 1:2021 is an international standard published by the ISO and IEC, focusing on information technology security techniques, specifically encryption algorithms. This amendment updates Part 5 of the ISO/IEC 18033 series, which addresses identity-based ciphers, by incorporating the SM9 mechanism. The SM9 mechanism is an identity-based public key encryption and key encapsulation method, enhancing cryptographic security options for secure communication.
The standard is a vital reference for cybersecurity professionals and technology developers who require rigorous and globally recognized encryption methods based on identity-based cryptography.
Key Topics
-
Identity-Based Encryption Algorithms: The standard details several identity-based encryption (IBE) and key encapsulation mechanisms (KEM), including:
- BF (Boneh-Franklin) IBE mechanism
- SK (Sakai-Kasahara) identity-based key encapsulation
- BB1 (Boneh-Boyen) key encapsulation
- SM9 identity-based key encapsulation and encryption mechanism (newly added in this amendment)
-
SM9 Mechanism Details:
The amendment specifies the SM9 key encapsulation mechanism’s setup, private key extraction, session key encapsulation, and de-encapsulation processes.
- Utilizes pairing-based cryptography over elliptic curve groups
- Employs specific hash functions including IHF2 based on KDF2 with the SM3 hash algorithm
- Defines secure cryptographic transformations and Object Identifiers (OIDs) for algorithm identification
-
Security Considerations:
Includes reference to detailed security analyses for all mechanisms involved, with SM9’s security substantiated in cited references.
-
Technical Annexes:
- Annex A defines object identifiers for SM9 related algorithms.
- Annex B provides security analysis summaries.
- Annex C offers numerical examples illustrating the SM9 mechanism.
- Annex D introduces techniques to reduce trust in the Private Key Generator (PKG).
Applications
-
Secure Communication Systems:
SM9 enables secure encryption and key exchange based on user identities, eliminating the need for traditional public key infrastructures (PKI).
-
Identity-Based Cryptography Implementation:
Useful for applications requiring efficient key management and strong encryption bound to user identities, such as secure email, instant messaging, and mobile networks.
-
Lightweight and Scalable Security Solutions:
The identity-based approach reduces certificate management overhead, benefiting constrained environments and large user bases.
-
Government and Enterprise Security:
Applicable where robust access control and confidentiality are mandatory, including defense communications, financial transactions, and privacy-centric services.
Related Standards
-
ISO/IEC 18033 Series:
- Part 2: Stream ciphers - Provides key derivation functions like KDF2 used by SM9
- Part 3: Block ciphers - Underlying block cipher methods referenced by SM9
-
ISO/IEC 10118-3:
Specifies the SM3 cryptographic hash function, integral to the SM9 algorithm’s secure hash computations.
-
ISO/IEC 14888-3:
Defines elliptic curve cryptography techniques, providing mathematical underpinnings relevant to the SM9 key encapsulation examples.
-
ISO/IEC Directives Part 1 and Part 2:
Describe procedures for the development and maintenance of ISO/IEC standards including editorial rules.
This amendment to ISO/IEC 18033-5 strengthens the portfolio of modern encryption algorithms by introducing a robust, identity-based encryption mechanism aligned with prevailing security needs. Incorporating the SM9 mechanism facilitates enhanced cryptographic practices supporting global information security infrastructures. For professionals in cybersecurity, software development, and standards compliance, adopting this standard ensures compatibility and trusted security across a wide range of identity-centric applications.