Overview - ISO/IEC 20009-3:2022: Anonymous entity authentication (blind signatures)
ISO/IEC 20009-3:2022 defines specifications for anonymous entity authentication mechanisms based on blind digital signatures. It describes a general model and concrete processes - parameter generation, key generation, credential issuance and authentication - that enable a claimant to prove possession of a credential without revealing their identity. The standard focuses on privacy-preserving authentication using blind signatures (as defined in the ISO/IEC 18370 series) and includes a two‑pass unilateral anonymous authentication mechanism.
Key topics and technical requirements
- Anonymous entity authentication model: Roles and interactions among issuer, claimant and verifier; domain model and required security properties.
- Mechanism processes: Clear specification of the four essential processes - domain parameter generation, key generation, credential issuance, and authentication - that collectively implement anonymous authentication.
- Unilateral anonymous authentication: Defines two‑pass mechanisms where the claimant is authenticated anonymously to the verifier (verifier does not reveal identity).
- Blind signature integration: Mechanisms are based on blind digital signatures (ISO/IEC 18370 series), enabling credential issuance without the issuer learning the claimant’s chosen secret values.
- Specification artifacts and appendices: Includes normative object identifiers (OIDs) and informative annexes covering conversion functions, group descriptions (finite field and elliptic curve constructions), special hash functions and security considerations.
- Security and privacy requirements: Emphasis on collision-resistant hash functions, unique encoding of concatenated items, domain parameters, and formal processes to ensure anonymity and verifiability.
Practical applications and target users
ISO/IEC 20009-3:2022 is intended for implementers and architects who need privacy-preserving authentication in systems such as:
- Anonymous credential systems and selective disclosure schemes
- Privacy-focused access control for online services and federated identity
- Electronic tokens, anonymous ticketing or vouchers where issuer privacy constraints apply
- Any application requiring unlinkable, verifiable credentials issued via blind-signature workflows
Primary users:
- Security architects and cryptographic engineers designing credential issuance and anonymous authentication protocols
- Standards and compliance teams evaluating privacy and cryptographic requirements
- Software vendors building identity/privacy-preserving platforms and middleware
Related standards
- ISO/IEC 18370 series - Blind digital signatures (foundation used by this part)
- ISO/IEC 9796 series - Digital signature schemes referenced for signature formats
- ISO/IEC 20009-1 - General concepts for anonymous entity authentication
Using ISO/IEC 20009-3:2022 helps organizations implement standardized, interoperable blind-signature based authentication that balances verifiability with strong privacy guarantees.