Overview
ISO/IEC 20009-1:2013 - "Information technology - Security techniques - Anonymous entity authentication - Part 1: General" defines a model, terminology, requirements and constraints for anonymous entity authentication mechanisms. The standard establishes how a claimant can prove legitimacy or possession of attributes without revealing a personal identifier to unauthorized parties, while allowing authorised verifiers to corroborate authenticity. It sets out the general framework used by the subsequent parts of ISO/IEC 20009 that specify concrete mechanisms.
Key topics and requirements
- Anonymous authentication model: formal roles (claimant, verifier, trusted third party (TTP)), message flows and token exchanges required for unilateral, mutual and unilateral-anonymous mutual authentication.
- Terms and definitions: standardized vocabulary such as anonymity strength, anonymous digital signature, opening, linking, opener, linker, claimant, verifier.
- General requirements and constraints:
- Common cryptographic techniques and parameters must be used by parties.
- Time-variant parameters (random numbers, sequence numbers, timestamps) must be non-repeating with overwhelming probability during key lifetime.
- Authentication guarantees apply only to the instant of the exchange; subsequent data requires secure session protection (e.g., integrity or MACs) established during authentication.
- Partially anonymous mechanisms must include data to enable authorized opening when required.
- Managing anonymity:
- Concepts of anonymity strength (size of anonymity set) and how environment/context affect anonymity.
- Processes that reduce anonymity: linking (showing multiple sessions were by the same entity) and opening (authorized re-identification).
Applications and who uses it
ISO/IEC 20009-1:2013 is applicable to systems needing privacy-preserving authentication, including:
- Electronic voting, electronic identities (e-passports, e-health IDs), e-driving licences
- Mobile payments, social networks, electronic business and trusted computing
Primary users:
- Security architects and protocol designers implementing anonymous authentication
- Cryptographic engineers and software developers building privacy-preserving services
- Standards bodies, compliance officers and auditors verifying conformance and privacy controls
Related standards
Keywords: ISO/IEC 20009-1:2013, anonymous entity authentication, anonymity strength, anonymous digital signature, opening, linking, privacy-preserving authentication.