Valid

GB/T 15843.5-2005Information technology -- Security technique -- Entity authentication -- Part 5: Mechanisms using zero knowledge techniques (English PDF)

Preview PDF

Also coversGBT15843.5-2005

This is a limited preview

Buy now to download the full PDF (17 pages)

Need quotation for your management?

Get a formal quotation for GB/T 15843.5-2005 in 30 minutes.

Issued by

General Administration of Quality Supervision, Inspection and Quarantine

Level / Type

National · Recommended

Issue date

April 19, 2005

Implementation date

October 1, 2005

Scope

GB/T 15843.5-2005 (Information technology -- Security technique -- Entity authentication -- Part 5: Mechanisms using zero knowledge techniques) is available as an English-translated PDF.

GB/T 15843.5-2005 is the Chinese standard "Information technology -- Security technique -- Entity authentication -- Part 5: Mechanisms using zero knowledge techniques".

Its scope clause reads: This Part of GB/T 15843 specifies three entity authentication mechanisms using zero knowledge techniques. All the mechanisms specified in this Part of GB/T 15843 provide unilateral authentication.

These mechanisms are constructed using the principles of zero knowledge, but they will not be zero knowledge according to the strict definition sketched in Annex A for all choices of parameters.

The first mechanism is said to be based on identities. A trusted accreditation authority provides each claimant with private accreditation information, computed as a function of the claimant's identification data and the accreditation authority's private key.

The second mechanism is said to be certificate-based using discrete logarithms. Every claimant possesses a public key, private key pair for use in this mechanism.

Every verifier of a claimant's identity must possess a trusted copy of the claimant 's public verification key; the means by which this is achieved is beyond the scope of this Standard, but it may be achieved through the distribution of certificates signed by a Trusted Third Party.

The third mechanism is said to be certificate-based using an asymmetric encipherment system. Every claimant possesses a public key, private key pair for an asymmetric cryptosystem.

Every verifier of a claimant's identity must possess a trusted copy of the claimant 's public key; the means by which this is achieved is beyond the scope of this Standard, but it may be achieved through the distribution of certificates signed by a Trusted Third Party. Its clauses include normative reference; terms and definitions.

Found what you need?

Document preview — GB/T 15843.5-2005

National Standard of the People's Republic of China

ICS
35.040
Classification
L 80

Issued by: General Administration of Quality Supervision, Inspection and Quarantine

Contents

  • Foreword4
  • 1 Scope5
  • 2 Normative Reference5
  • 3 Terms and Definitions6
  • 4 Symbols and Notation8
  • 5 Mechanism Based on Identities11
  • 5.1 Specific requirements11
  • 5.2 Parameter selection11
  • 5.3 Identity selection12
  • 5.4 Accreditation generation13
  • 5.5 Authentication exchange13
  • 6 Certificate-Based Mechanism Using Discrete Logarithms16
  • 6.1 Specific requirements16
  • 6.2 Key selection17
  • 6.3 Authentication exchange17
  • 7.1 Specific requirements20
  • 7.2 Authentication exchange20
  • Annex A (Normative) Principles of Zero Knowledge Mechanisms23
  • A.1 Introduction23
  • A.2 The need for zero-knowledge mechanisms23
  • A.3 The definition24
  • A.4 An example25
  • A.5 Basic design principles27
  • Annex B (Informative) Guidance on Parameter Choice28
  • B.1 Parameter choice for the identity-based mechanism28
  • Annex C (Informative) Examples30
  • C.1 Mechanism based on identities30
  • C.1.1 Example with public exponent 230
  • C.1.2 Example with public exponent 334
  • C.1.3 Example with public exponent 216 + 139
  • C.2 Mechanism based on discrete logarithms40
  • C.2.1 Example using 768-bit p, 128-bit q and RIPEMD-12840
  • C.2.2 Example using 1024-bit p, 160-bit q and SHA-142
  • C.3 Mechanism based on a trusted public transformation44
  • C.3.1 Example using 767-bit RSA and RIPEMD-16044
  • C.3.2 Example using 1024-bit RSA and SHA-146
  • Annex D (Informative) Comparison of the Mechanism48
  • D.1 Measures for comparing the mechanisms48
  • D.2 Mechanism based on identities49
  • D.2.1 The case where v is large (e.g. the Guillou-Quisquater scheme)49
  • D.2.2 Fiat-Shamir scheme51
  • D.3 Certificate-based mechanism using discrete logarithms52
  • D.3.1 Computational complexity52
  • D.3.2 Communication complexity53
  • D.3.3 Size of the claimant's accreditations53
  • D.3.4 Degree of security53
  • D.4 Certificate-based mechanism using an asymmetric encipherment system53
  • D.4.1 Computational complexity53
  • D.4.2 Communication complexity54
  • D.4.3 Size of the claimant's accreditations54
  • D.4.4 Degree of security54
  • D.5 Comparison of the mechanisms54
  • Annex E (Informative) Information about Patents56
  • Annex F (Informative) Bibliography57

1 Scope

This Part of GB/T 15843 specifies three entity authentication mechanisms using zero knowledge techniques. All the mechanisms specified in this Part of GB/T 15843 provide unilateral authentication. These mechanisms are constructed using the principles of zero knowledge, but they will not be zero knowledge according to the strict definition sketched in Annex A for all choices of parameters.

The first mechanism is said to be based on identities. A trusted accreditation authority provides each claimant with private accreditation information, computed as a function of the claimant's identification data and the accreditation authority's private key.

The second mechanism is said to be certificate-based using discrete logarithms. Every claimant possesses a public key, private key pair for use in this mechanism. Every verifier of a claimant's identity must possess a trusted copy of the claimant 's public verification key; the means by which this is achieved is beyond the scope of this

Standard, but it may be achieved through the distribution of certificates signed by a

Trusted Third Party.

The third mechanism is said to be certificate-based using an asymmetric encipherment system. Every claimant possesses a public key, private key pair for an asymmetric cryptosystem. Every verifier of a claimant's identity must possess a trusted copy of the claimant 's public key; the means by which this is achieved is beyond the scope of this

Standard, but it may be achieved through the distribution of certificates signed by a

Trusted Third Party.

2 Normative Reference

The provisions in following documents become the provisions of this Part through reference in this Part of GB/T 15843. For dated references, the subsequent amendments (excluding corrigendum) or revisions do not apply to this Part, however, parties who reach an agreement based on this Standard are encouraged to study if the latest versions of these documents are applicable. For undated references, the latest edition of the referenced document applies.

GB 15851-1995 Information Technology - Security Techniques - Digital Signature

Scheme Giving Message Recovery (idt ISO/IEC 9796:1991)

GB/T 15843.1-1999 Information Technology - Security Techniques - Entity

Authentication - Part 1: General (idt ISO/IEC 9798-1:1997)

GB/T 18238 (all parts) Information Technology - Security Techniques - Hash-

Function (idt ISO/IEC 10118)

3 Terms and Definitions

For the purpose of this Part of GB/T 15843, the terms and definitions given in GB/T 15843.1-1999 and the following apply.

3.1 Asymmetric cryptographic technique

3.2 Asymmetric encipherment system

3.3 Asymmetric key pair

3.4 Challenge

3.5 Claimant

3.6 Decipherment

3.7 Distinguishing identifier

3.8 Encipherment

3.9 Entity authentication

3.10 Private key

3.11 Public key

3.12 Public verification key

3.13 Random number

3.14 Token

3.15 Trusted third party

3.16 Unilateral authentication

3.17 Verifier

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 17 pages — is available in the English PDF.

Referenced standards

How to Download GB/T 15843.5-2005

  1. 1

    Add to cart

    Click "Download PDF" on this page and choose "Buy this standard". You can add more standards before checkout.

  2. 2

    Checkout

    Enter your email and billing details. Payment is processed securely by Stripe (cards or bank transfer). Prefer bank details? Request a quotation (min. order $300).

  3. 3

    Instant delivery (0–9 sec)

    Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.

  4. 4

    Invoice included

    A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
17 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 15843.5-2005

$245.00