GB/T 15843.5-2005Information technology -- Security technique -- Entity authentication -- Part 5: Mechanisms using zero knowledge techniques (English PDF)
Also coversGBT15843.5-2005
This is a limited preview
Buy now to download the full PDF (17 pages)
Need quotation for your management?
Get a formal quotation for GB/T 15843.5-2005 in 30 minutes.
Issued by
General Administration of Quality Supervision, Inspection and Quarantine
Level / Type
National · Recommended
Issue date
April 19, 2005
Implementation date
October 1, 2005
Scope
GB/T 15843.5-2005 (Information technology -- Security technique -- Entity authentication -- Part 5: Mechanisms using zero knowledge techniques) is available as an English-translated PDF.
GB/T 15843.5-2005 is the Chinese standard "Information technology -- Security technique -- Entity authentication -- Part 5: Mechanisms using zero knowledge techniques".
Its scope clause reads: This Part of GB/T 15843 specifies three entity authentication mechanisms using zero knowledge techniques. All the mechanisms specified in this Part of GB/T 15843 provide unilateral authentication.
These mechanisms are constructed using the principles of zero knowledge, but they will not be zero knowledge according to the strict definition sketched in Annex A for all choices of parameters.
The first mechanism is said to be based on identities. A trusted accreditation authority provides each claimant with private accreditation information, computed as a function of the claimant's identification data and the accreditation authority's private key.
The second mechanism is said to be certificate-based using discrete logarithms. Every claimant possesses a public key, private key pair for use in this mechanism.
Every verifier of a claimant's identity must possess a trusted copy of the claimant 's public verification key; the means by which this is achieved is beyond the scope of this Standard, but it may be achieved through the distribution of certificates signed by a Trusted Third Party.
The third mechanism is said to be certificate-based using an asymmetric encipherment system. Every claimant possesses a public key, private key pair for an asymmetric cryptosystem.
Every verifier of a claimant's identity must possess a trusted copy of the claimant 's public key; the means by which this is achieved is beyond the scope of this Standard, but it may be achieved through the distribution of certificates signed by a Trusted Third Party. Its clauses include normative reference; terms and definitions.
Found what you need?
Document preview — GB/T 15843.5-2005
National Standard of the People's Republic of China
- ICS
- 35.040
- Classification
- L 80
Issued by: General Administration of Quality Supervision, Inspection and Quarantine
Contents
- Foreword4
- 1 Scope5
- 2 Normative Reference5
- 3 Terms and Definitions6
- 4 Symbols and Notation8
- 5 Mechanism Based on Identities11
- 5.1 Specific requirements11
- 5.2 Parameter selection11
- 5.3 Identity selection12
- 5.4 Accreditation generation13
- 5.5 Authentication exchange13
- 6 Certificate-Based Mechanism Using Discrete Logarithms16
- 6.1 Specific requirements16
- 6.2 Key selection17
- 6.3 Authentication exchange17
- 7.1 Specific requirements20
- 7.2 Authentication exchange20
- Annex A (Normative) Principles of Zero Knowledge Mechanisms23
- A.1 Introduction23
- A.2 The need for zero-knowledge mechanisms23
- A.3 The definition24
- A.4 An example25
- A.5 Basic design principles27
- Annex B (Informative) Guidance on Parameter Choice28
- B.1 Parameter choice for the identity-based mechanism28
- Annex C (Informative) Examples30
- C.1 Mechanism based on identities30
- C.1.1 Example with public exponent 230
- C.1.2 Example with public exponent 334
- C.1.3 Example with public exponent 216 + 139
- C.2 Mechanism based on discrete logarithms40
- C.2.1 Example using 768-bit p, 128-bit q and RIPEMD-12840
- C.2.2 Example using 1024-bit p, 160-bit q and SHA-142
- C.3 Mechanism based on a trusted public transformation44
- C.3.1 Example using 767-bit RSA and RIPEMD-16044
- C.3.2 Example using 1024-bit RSA and SHA-146
- Annex D (Informative) Comparison of the Mechanism48
- D.1 Measures for comparing the mechanisms48
- D.2 Mechanism based on identities49
- D.2.1 The case where v is large (e.g. the Guillou-Quisquater scheme)49
- D.2.2 Fiat-Shamir scheme51
- D.3 Certificate-based mechanism using discrete logarithms52
- D.3.1 Computational complexity52
- D.3.2 Communication complexity53
- D.3.3 Size of the claimant's accreditations53
- D.3.4 Degree of security53
- D.4 Certificate-based mechanism using an asymmetric encipherment system53
- D.4.1 Computational complexity53
- D.4.2 Communication complexity54
- D.4.3 Size of the claimant's accreditations54
- D.4.4 Degree of security54
- D.5 Comparison of the mechanisms54
- Annex E (Informative) Information about Patents56
- Annex F (Informative) Bibliography57
1 Scope
This Part of GB/T 15843 specifies three entity authentication mechanisms using zero knowledge techniques. All the mechanisms specified in this Part of GB/T 15843 provide unilateral authentication. These mechanisms are constructed using the principles of zero knowledge, but they will not be zero knowledge according to the strict definition sketched in Annex A for all choices of parameters.
The first mechanism is said to be based on identities. A trusted accreditation authority provides each claimant with private accreditation information, computed as a function of the claimant's identification data and the accreditation authority's private key.
The second mechanism is said to be certificate-based using discrete logarithms. Every claimant possesses a public key, private key pair for use in this mechanism. Every verifier of a claimant's identity must possess a trusted copy of the claimant 's public verification key; the means by which this is achieved is beyond the scope of this
Standard, but it may be achieved through the distribution of certificates signed by a
Trusted Third Party.
The third mechanism is said to be certificate-based using an asymmetric encipherment system. Every claimant possesses a public key, private key pair for an asymmetric cryptosystem. Every verifier of a claimant's identity must possess a trusted copy of the claimant 's public key; the means by which this is achieved is beyond the scope of this
Standard, but it may be achieved through the distribution of certificates signed by a
Trusted Third Party.
2 Normative Reference
The provisions in following documents become the provisions of this Part through reference in this Part of GB/T 15843. For dated references, the subsequent amendments (excluding corrigendum) or revisions do not apply to this Part, however, parties who reach an agreement based on this Standard are encouraged to study if the latest versions of these documents are applicable. For undated references, the latest edition of the referenced document applies.
GB 15851-1995 Information Technology - Security Techniques - Digital Signature
Scheme Giving Message Recovery (idt ISO/IEC 9796:1991)
GB/T 15843.1-1999 Information Technology - Security Techniques - Entity
Authentication - Part 1: General (idt ISO/IEC 9798-1:1997)
GB/T 18238 (all parts) Information Technology - Security Techniques - Hash-
Function (idt ISO/IEC 10118)
3 Terms and Definitions
For the purpose of this Part of GB/T 15843, the terms and definitions given in GB/T 15843.1-1999 and the following apply.
3.1 Asymmetric cryptographic technique
3.2 Asymmetric encipherment system
3.3 Asymmetric key pair
3.4 Challenge
3.5 Claimant
3.6 Decipherment
3.7 Distinguishing identifier
3.8 Encipherment
3.9 Entity authentication
3.10 Private key
3.11 Public key
3.12 Public verification key
3.13 Random number
3.14 Token
3.15 Trusted third party
3.16 Unilateral authentication
3.17 Verifier
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 17 pages — is available in the English PDF.
Referenced standards
How to Download GB/T 15843.5-2005
- 1
Add to cart
Click "Download PDF" on this page and choose "Buy this standard". You can add more standards before checkout.
- 2
Checkout
Enter your email and billing details. Payment is processed securely by Stripe (cards or bank transfer). Prefer bank details? Request a quotation (min. order $300).
- 3
Instant delivery (0–9 sec)
Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4
Invoice included
A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 15843.1-2017 — Information technology -- Security techniques -- Entity authentication -- Part 1: General
GB/T 15843.3-2023 — Information technology—Security techniques—Entity authentication—Part 3: Mechanisms using digital signature techniques
GB/T 15843.4-2024 — Information technology - Security techniques - Entity authentication - Part 4: Mechanisms using a cryptographic check function
Secure payment via Stripe
Payments accepted
GB/T 15843.5-2005
$245.00