Overview
ISO/IEC 7816-8:2021/Amd 1:2023 is an amendment to Part 8 of the ISO/IEC 7816 series for identification cards - integrated circuit cards (ICCs). It adds interoperability features for the interchange of security operations using quantum safe cryptography (QSC). The amendment defines generic QSC functionality, new terminology for quantum-safe algorithms, and reusable template structures to enable crypto‑agility and hybrid cryptography on smart cards and similar secure elements.
Key topics and technical requirements
- New normative reference: ISO/IEC 7816-4:2020 is cited for related data object (DO) coding rules.
- Terminology additions: Definitions for terms such as quantum safe, quantum safe cryptography, certificate chain, key encapsulation algorithm (KEM) and specific algorithms (e.g., CRYSTALS-Dilithium, CRYSTALS-Kyber, Classic McEliece, FALCON, SPHINCS+, LMS, XMSS, NTRU, Saber, FrodoKEM).
- QSC templates and data objects: Introduction of standardized template DOs - DO’7F75’, DO’7F76’, DO’7F77’ - to encapsulate private keys, public keys and common parameters for QSC. Templates use data object tags such as DO’81’ (Key type), DO’82’ (Key size), DO’9X’ (Key value components), DO’8F’ (Key identifier), and optional DO’5C’ (Parameters Organization Descriptor) to support complex or repeated parameter sets.
- Storage and interoperability rules: Guidance on where private/public keys may be stored (e.g., internal EF, DO’7F48’, QSC templates) and how QSC objects are coded to support exchange of security operations across systems.
- Crypto‑agility and hybrid support: The amendment targets generic QSC features to accommodate different families of quantum‑safe algorithms and hybrid certificates that combine classical and quantum‑safe signatures.
Practical applications
- Modernizing smart cards, eID, authentication tokens, and secure elements to support quantum‑resistant cryptography.
- Implementing signature and key‑encapsulation operations (KEMs) on ICCs with standardized templates for cross‑vendor interoperability.
- Supporting migration strategies (crypto‑agility, hybrid certificates) where both classic and quantum‑safe algorithms coexist during transition.
Who should use this standard
- Smart card and secure element manufacturers and firmware developers
- Card operating-system vendors and middleware implementers
- PKI designers, certificate authorities, and integrators planning quantum‑safe deployment
- Security architects and system integrators concerned with long‑term integrity of card-based authentication and signatures
Related standards
- ISO/IEC 7816 series (cards and security devices for personal identification)
- ISO/IEC 7816-4:2020 (data object and file structure rules referenced by the amendment)
Keywords: ISO/IEC 7816-8 amendment, quantum safe cryptography, QSC, smart cards, integrated circuit cards, crypto-agility, DO7F75, DO7F76, DO7F77, quantum-resistant algorithms.