Overview
ISO/IEC 29191:2012 - Information technology - Security techniques - Requirements for partially anonymous, partially unlinkable authentication - defines a framework and requirements for authentication that preserves user privacy while allowing controlled re‑identification. Published by ISO/IEC JTC 1/SC 27, the standard addresses situations where complete anonymity is undesirable but users still need protection from routine tracking. Keywords: partially anonymous authentication, unlinkable authentication, privacy‑preserving authentication, re‑identification, designated opener.
Key topics
- Scope and purpose: Establishes a framework and high‑level requirements for systems that provide partial anonymity and unlinkability, while enabling an a priori designated party to re‑identify a claimant when appropriate.
- Core concepts and terms: Credential, claimant, issuer, verifier, designated opener, transcript of authentication, re‑identification.
- Framework roles and operations:
- Roles: Issuer, Claimant, Verifier, Designated opener.
- Operations: credential issuing, designated opener setup, authentication (producing a transcript), and re‑identification.
- Privacy‑security balance:
- Verifier must authenticate without identifying the claimant.
- Transcripts must not by themselves link multiple sessions (unlinkability).
- Transcripts must contain sufficient information for the designated opener to re‑identify the claimant if allowed.
- The designated opener must be able to provide evidence that re‑identification was correctly and legitimately performed.
- Process lifecycle: Registration/enrollment (including anonymity setup), authentication, (authorization - out of scope), and re‑identification when justified.
Practical applications
ISO/IEC 29191 is applicable where user privacy and accountability must coexist:
- Library systems: enable anonymous borrowing records while allowing a librarian head (designated opener) to identify overdue borrowers.
- Intelligent Traffic Systems (ITS): issue temporary identifiers for vehicles to analyze flow and tolls, with re‑identification permitted for billing or law enforcement.
- E‑commerce and payments: allow verification of billing account validity without revealing full account numbers; banks can act as designated openers for billing or dispute resolution.
These scenarios illustrate privacy‑preserving authentication for access control, data protection, billing, and traffic analysis.
Who should use this standard
- Security architects and privacy engineers designing authentication systems that require conditional re‑identification.
- System integrators for ITS, libraries, payment gateways and smart‑card or RFID deployments.
- Policy makers and compliance officers specifying privacy and accountability controls.
- Developers implementing cryptographic credentials and audit trails that must support unlinkability with controlled opening.
Related standards