General Information

Abstract

Status
Not Published
Current Stage
5020 - FDIS ballot initiated: 2 months. Proof sent to secretariat
Start Date
20-Aug-2026
Completion Date
20-Aug-2026

Buy Documents

Draft

ISO/IEC 14888-3:2018/FDAmd 1 - IT Security techniques — Digital signatures with appendix — Part 3: Discrete logarithm based mechanisms — Amendment 1

Release Date:06-Aug-2026
English language (17 pages)
sale 15% off
sale 15% off
Draft

REDLINE ISO/IEC 14888-3:2018/FDAmd 1 - IT Security techniques — Digital signatures with appendix — Part 3: Discrete logarithm based mechanisms — Amendment 1

Release Date:06-Aug-2026
English language (17 pages)
sale 15% off
sale 15% off

Overview

ISO/IEC 14888-3:2018/FDAmd 1:2026 is an amendment to the international standard for IT security techniques, specifically focusing on digital signatures with appendix based on discrete logarithm mechanisms. Developed by the ISO/IEC JTC 1/SC 27 committee, this document introduces updates and enhancements to support more robust, secure, and efficient digital signature algorithms. One key development in this amendment is the inclusion of EdDSA (Edwards Curve Digital Signature Algorithm) alongside a comprehensive suite of discrete logarithm-based digital signature mechanisms.

This standard is highly relevant to cybersecurity professionals, cryptographic system implementers, and organizations requiring strong authentication and data integrity through digital signature schemes that adhere to internationally recognized security techniques.

Key Topics

  • Extended Mechanism Support: The amendment incorporates EdDSA (Edwards Curve Digital Signature Algorithm), which uses twisted Edwards curves and has become widely adopted due to its security and efficiency advantages.
  • Normative References Update: It adds hash function requirements from ISO/IEC 29192-5, expanding support for lightweight cryptography and modern hash algorithms.
  • Updated Definitions and Symbols: Clarifies terminology and mathematical definitions, such as the “complete twisted Edwards curve group,” ensuring a strong foundation for cryptographic implementations.
  • Security Protections: Includes discussions on preventing key substitution attacks in elliptic curve mechanisms and highlights architectural protections, such as embedding public key information in the message hash.
  • Annex Updates: Expands and reorganizes annexes to detail point encoding and decoding procedures for EdDSA and provide cryptographic object identifiers for all supported mechanisms.
  • Algorithm Parameter Framework: Details ASN.1 module structures and digital signature algorithm identification for interoperability in practical implementation.

Applications

Implementing ISO/IEC 14888-3:2018/FDAmd 1:2026 is critical in the following scenarios:

  • Secure Communications: Establishing tamper-proof, authenticated digital documents and secure email exchanges using robust digital signature verification.
  • Public Key Infrastructure (PKI): Foundations for certificate authorities and digital identity providers, using standard, globally recognized digital signature algorithms.
  • Financial Transactions: Enhancing the security of electronic transactions, blockchain entries, and e-commerce payment services by relying on approved signature schemes.
  • Regulatory Compliance: Satisfying international and national regulatory requirements for digital signature strength and cryptographic interoperability.
  • Device and Embedded Security: Ensuring lightweight cryptography options for Internet of Things (IoT) and embedded systems through support for efficient mechanisms such as EdDSA.
  • Open-Source and Commercial Software: Giving assurance of cryptographic best practices in widely adopted libraries and applications, including those aligned with RFC 8032 and FIPS 186-5 standards.

Related Standards

This amendment aligns with and references several other key international standards, providing consistency and interoperability across digital signature applications:

  • ISO/IEC 14888 Series: Core standards for digital signature mechanisms.
  • ISO/IEC 10118-3: Security techniques for hash functions - critical for signature generation and verification.
  • ISO/IEC 29192-5: Security techniques for lightweight hash-functions, supporting resource-constrained environments.
  • FIPS 186-5: Digital Signature Standard (DSS) by NIST, a major reference for U.S. federal digital signature adoption.
  • RFC 8032: The IETF specification for Edwards-Curve Digital Signature Algorithm (EdDSA), ensuring protocol compatibility and open implementation.

By providing clear definitions, comprehensive algorithm support, and international interoperability, ISO/IEC 14888-3:2018/FDAmd 1:2026 serves as a foundational standard for secure, modern digital signature implementations leveraging discrete logarithm-based cryptography.

Relations

Effective Date
04-May-2024

Buy Documents

Draft

ISO/IEC 14888-3:2018/FDAmd 1 - IT Security techniques — Digital signatures with appendix — Part 3: Discrete logarithm based mechanisms — Amendment 1

Release Date:06-Aug-2026
English language (17 pages)
sale 15% off
sale 15% off
Draft

REDLINE ISO/IEC 14888-3:2018/FDAmd 1 - IT Security techniques — Digital signatures with appendix — Part 3: Discrete logarithm based mechanisms — Amendment 1

Release Date:06-Aug-2026
English language (17 pages)
sale 15% off
sale 15% off

Get Certified

Connect with accredited certification bodies for this standard

BSI Group

BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

UKAS United Kingdom Verified

Bureau Veritas

Bureau Veritas is a world leader in laboratory testing, inspection and certification services.

COFRAC France Verified

DNV

DNV is an independent assurance and risk management provider.

NA Norway Verified

Sponsored listings

Frequently Asked Questions

ISO/IEC 14888-3:2018/FDAmd 1 is a draft published by the International Organization for Standardization (ISO). Its full title is "IT Security techniques — Digital signatures with appendix — Part 3: Discrete logarithm based mechanisms — Amendment 1". This standard covers: IT Security techniques — Digital signatures with appendix — Part 3: Discrete logarithm based mechanisms — Amendment 1

IT Security techniques — Digital signatures with appendix — Part 3: Discrete logarithm based mechanisms — Amendment 1

ISO/IEC 14888-3:2018/FDAmd 1 is classified under the following ICS (International Classification for Standards) categories: 35.030 - IT Security. The ICS classification helps identify the subject area and facilitates finding related standards.

ISO/IEC 14888-3:2018/FDAmd 1 has the following relationships with other standards: It is inter standard links to ISO/IEC 14888-3:2018. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.

ISO/IEC 14888-3:2018/FDAmd 1 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


FINAL DRAFT
Amendment
ISO/IEC
14888-3:2018/
FDAM 1
ISO/IEC JTC 1/SC 27
IT Security techniques — Digital
Secretariat: DIN
signatures with appendix —
Voting begins on:
2026-08-20
Part 3:
Discrete logarithm based
Voting terminates on:
2026-10-15
mechanisms
AMENDMENT 1
Techniques de sécurité IT — Signatures numériques avec
appendice —
Partie 3: Mécanismes basés sur un logarithme discret
AMENDEMENT 1
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
IN ADDITION TO THEIR EVALUATION AS
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO­
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
Reference number
ISO/IEC 14888­3:2018/FDAM 1:2026(en) © ISO/IEC 2026

FINAL DRAFT
ISO/IEC 14888-3:2018/FDAM 1:2026(en)
Amendment
ISO/IEC
14888-3:2018/
FDAM 1
ISO/IEC JTC 1/SC 27
IT Security techniques — Digital
Secretariat: DIN
signatures with appendix —
Voting begins on:
Part 3:
Discrete logarithm based
Voting terminates on:
mechanisms
AMENDMENT 1
Techniques de sécurité IT — Signatures numériques avec
appendice —
Partie 3: Mécanismes basés sur un logarithme discret
AMENDEMENT 1
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
© ISO/IEC 2026
IN ADDITION TO THEIR EVALUATION AS
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO­
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
or ISO’s member body in the country of the requester.
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland Reference number
ISO/IEC 14888­3:2018/FDAM 1:2026(en) © ISO/IEC 2026

© ISO/IEC 2026 – All rights reserved
ii
ISO/IEC 14888-3:2018/FDAM 1:2026(en)
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical activity.
ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations,
governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of document should be noted. This document was drafted in accordance with the editorial rules of the ISO/
IEC Directives, Part 2 (see www.iso.org/directives or www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the
use of (a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any
claimed patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not
received notice of (a) patent(s) which may be required to implement this document. However, implementers
are cautioned that this may not represent the latest information, which may be obtained from the patent
database available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall not be held
responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 27, Information security, cyber security, and privacy protection.
A list of all parts in the ISO/IEC 14888 series can be found on the ISO and IEC websites.
Any feedback or questions on this document should be directed to the user’s national standards
body. A complete listing of these bodies can be found at www.iso.org/members.html and
www.iec.ch/national-committees.

© ISO/IEC 2026 – All rights reserved
iii
ISO/IEC 14888-3:2018/FDAM 1:2026(en)
IT Security techniques — Digital signatures with appendix —
Part 3:
Discrete logarithm based mechanisms
AMENDMENT 1
Introduction
After Note 4, replace the paragraph with the following text:
This document includes 15 mechanisms: two of which (DSA and Pointcheval/Vaudenay algorithm) were in
ISO/IEC 14888-3:1998, three of which (EC-DSA, EC-KCDSA, and EC-GDSA) were from ISO/IEC 15946-2:2002,
three of which (KCDSA, IBS-1 and IBS-2) were added in ISO/IEC 14888-3:2006, four of which (SDSA, EC-
RDSA, EC-SDSA and EC-FSDSA) were added in ISO/IEC 14888-3:2006/Amd 1:2010, two of which (SM2 and
Chinese IBS) were added in ISO/IEC 14888-3:2018 and one of which (EdDSA) is added in this document.
Reword Note 5 as follows:
The mechanisms of EC-DSA, EC-GDSA, EC-RDSA and EC-FSDSA can be vulnerable to a key substitution attack.
[10]
The attack is realized if an adversary can find two distinct public keys and one signature such that the
signature is valid for both public keys. There are several approaches to avoiding this attack and its possible
impact on the security of a cryptographic system. For example, the public key corresponding to the private
signing key can be added into the message to be signed. EdDSA includes this protection in its design.

Clause 2, Normative references
Add the following:
ISO/IEC 29192-5, Information technology — Security techniques — Lightweight cryptography — Part 5: Hash-
functions
Clause 3, Terms and definitions
Insert the following definition after 3.6:
3.7
complete twisted Edwards curve group
cyclic group (3.2) defined on the points of a complete twisted Edwards curve over a finite field
Note 1 to entry Let FrGF be a finite field where r is an odd prime. Let a and d be distinct non-zero elements of

22 22
F such that a is a square in F and d is a non-square in F. Then the affine curve ax yd1 xy is a complete
twisted Edwards curve defined over F. The set E of points of this curve consists of a collection of certain affine points
from FF× , namely those that satisfy the curve equation. Let “+” denote the binary operation known as “Edwards-
curve addition”, defined for all affine points of E by

© ISO/IEC 2026 – All rights reserved
ISO/IEC 14888-3:2018/FDAM 1:2026(en)
xy,, xy xy xy /,11dx xy yy ya xx / dxxx yy .
     
11 22 12 21 12 12 12 12 12 12
The identity element for “+” is 01, . The set E together with the binary operation “+” forms a finite

commutative group E that is the complete twisted Edwards curve group for this curve.

Clause 4, Symbols and abbreviated terms
Add the following symbols/abbreviated terms:
ad,
twisted Edwards curve coefficients
EdDSA Edwards curve Digital Signature Algorithm
Replace the definition of E with the following:

E
an elliptic curve defined by two elliptic curve coefficients, a and a , or a twisted Edwards curve
1 2
defined by two curve coefficients a and d
Replace the definition of E with the following:
E
a finite commutative group; for the mechanisms based on a multiplicative group, the elements of E
*
are in Z ; for the mechanisms based on an additive group of elliptic curve points, the elements of E
p
are the points on an elliptic curve E over GF(r) or the points on the twisted Edwards curve E over GF(r)
Replace the definition of #E with the following:
#E the cardinality of E; for the mechanisms based on a multiplicative group Z *, #E is p − 1; for the
p
mechanisms based on an additive group of elliptic curve points, #E is one more than the number of
points on the elliptic curve E over GF(r) [including 0 (the point at infinity)]; for the mechanisms
E
based on twisted Edwards curve points, #E is the number of points on the twisted Edwards curve
E over GF(r)
5.2.2
At the end of Note 2, add the text:
Mechanisms can also permit a larger range for K or specify some algebraic format of K .

5.3.5
Add the following text at the end of the subclause:
For EdDSA the verification mechanism is specified in 6.13.

6.1
Replace the first paragraph with the following:

© ISO/IEC 2026 – All rights reserved
ISO/IEC 14888-3:2018/FDAM 1:2026(en)
Clause 6 specifies twelve certificate-based mechanisms. These make use of arithmetic in the multiplicative
group Z *, the additive group of elliptic curve points, or the additive group of points on twisted Edwards
p
curves. The mechanisms using arithmetic in the multiplicative group Z *, are the Digital Signature Algorithm
p
(DSA), the Korean Certificate-based Digital Signature Algorithm (KCDSA), the Pointcheval/Vaudenay
algorithm, and the Schnorr Digital Signature Algorithm (SDSA). The mechanisms using arithmetic in the
additive group of elliptic curve points are the Elliptic Curve DSA (EC-DSA), the Elliptic Curve KCDSA (EC-
KCDSA), the Elliptic Curve German Digital Signature Algorithm (EC-GDSA), the Elliptic Curve Russian Digital
Signature Algorithm (EC-RDSA), the Elliptic Curve Schnorr Digital Signature Algorithm (EC-SDSA), the
Elliptic Curve Full Schnorr Digital Signature Algorithm (EC-FSDSA), the SM2 algorithm, and the Edwards-
curve Digital Signature Algorithm (EdDSA).

At the end of the second paragraph insert the text:
The curves Ed25519 and Ed448 for EdDSA are specified in 6.13.

6.3.2
Replace the penultimate paragraph (starting "Three choices") with the following:
The pair (α,β) for KCDSA shall be chosen in accordance with the chosen security level, as shown in Table 1 in
5.1.3.1. Typical examples are (2 048, 224) and (3 072, 256).
The hash-function h shall be one of the approved hash-functions from ISO/IEC 10118-3 and ISO/IEC 29192-5.
The security strength γ of the hash-function h shall meet or exceed the security strength associated with the
pair (α,β).
6.5.2
Replace the paragraph under the listing (starting "Four choices") with the following:
Three choices for α are permitted in SDSA, namely 1 024, 2 048, and 3 072. The values of γ and β shall be
selected in accordance with the value of α, as specified in Table 1 in 5.1.3.1, such that γ ≥ β. The hash-function
h shall be one of the approved hash-functions from ISO/IEC 10118-3, and its security strength shall meet or
exceed the security strength associated with the pair (α,β).

6.6.1
In the second paragraph, replace the last sentence "The hash-function h . 10118-3" with the following.
The hash function h shall be one of SHA-224, SHA-512/224, SHA3-224, SHA-256, SHA-512/256, SHA3-256,
SHAKE-128 (d=256 bits), SHA-384, SHA3-384, SHA-512, SHA3-512, and SHAKE-256 (d=512 bits) specified
in ISO/IEC 10118-3. The security level γ shall meet or exceed the level associated with the parameter α (see
Table 1 in 5.1.3.1).
6.12.5.7
Add the following text after 6.12.5.7:
6.13  EdDSA
6.13.1  General
EdDSA (Edwards Curve Digital Signature Algorithm) is a signature mechanism with verification key Y′ equal
to the encoding of YX  G , where G is a specified point on a twisted Edwards curve and X is a multiple of
 
© ISO/IEC 2026 – All rights reserved
ISO/IEC 14888-3:2018/FDAM 1:2026(en)
8. The parameter D is equal to 1. The message is prepared such that M is empty and MM= , the message
1 2
to be signed. The witness R is computed as the encoding of LK  G for randomizer K .
 
The coefficients AB,,C of the EdDSA signature formula are set as

AB,,CT ,,TS ,
 

where TT ,,TH1  RYM and H is the hash function defined in 6.13.2.
 
Thus, the signature formula becomes KT XS0modq .
NOTE The mechanism is taken from Reference [47]. The notation here has been changed from Reference [47] to
conform with the notation used in the ISO/IEC 14888 series.
6.13.2  Parameters
Table 2 lists the parameters for Ed25519 and Ed448 which use the complete twisted Edwards curve group
defined by a and d modulo p.
Table 2 — Parameters for Ed25519 and Ed448
Ed25519 Ed448
p 255 448 224
21− 9 22−−1
b 256 456
c 8 4
t 32 57
H′(x) SHA-512(x) SHAKE256(x,114)
H(x) SHA-512(x) SHAKE256(dom4(0,context) || x, 114)
d −121665 / 121666 −39081
a −1 1
For Ed448, dom4(0,context) is the octet string "SigEd448" || octet(0) ||octet(OLEN(context)) || context, where
context is an octet string of at most 255 octets and OLEN(context) denotes its length in octets. "SigEd448" is
in ASCII (8 octets).
The base point G of order q2 27742317777372353535851937790883648493 on Ed25519 has
coordinates xy, where x is

and y is
The base point G of order q =
2 −138180668098951153520073867485154268803366924748821786609894547503885
on Ed448 has coordinates xy, , where x is

and y is
© ISO/IEC 2026 – All rights reserved
ISO/IEC 14888-3:2018/FDAM 1:2026(en)
6.13.3   Generation of signature key and verification key
The signature key of a signing entity is a secretly generated random or pseudo-random bitstring X ' of
length b .
′
The integer X , so that YX  G , is derived from X through hashing and processing.
 
 
For Ed25519 take HX SHA-512 X , storing the digest in a 64-octet large buffer. Set the lowest three
 
bits of the first octet to 0. Set the highest bit of the t-th octet to 0. Set the second highest bit of the t-th octet to
1. Interpret the first t octets as a little-endian integer, forming a secret integer X .
For Ed448 take HX SHAKE256 X,114 , storing the digest in a 114-octet large buffer. Set the lowest
 
two bits of the first octet to 0. Set all eight bits of the t-th octet to 0. Set the highest bit of the (t-1)-st octet to
1. Interpret the first t octetsas a little-endian integer, forming a secret integer X .
′
EdDSA specifies the verification key Y as the encoding of the point YX  G . The y -coordinate in the
 
range 0yp is encoded as a little-endian string of t octets. The most significant bit of the final octet is
always zero. To form the encoding of the point XG , copy the least significant bit of the x -coordinate to
 
the most significant bit of the final octet. The result is the verification key.
6.13.4  Signature process
6.13.4.1  Producing the randomizer and decoding the secret integer
′
The signing entity computes the pseudo-random integer K using the private signing key X and the message
M using the following two steps. The first step also recovers the secret integer X used in the signature
equation.

— Compute hH X of 2t octets. Construct the secret integer X from the first half of H as in

6.13.3. Let s denote the second half of the hash digest, ht ,.,ht21  .
   
— Compute HsM of 2t octets and interpret the digest as a little-endian integer K .

6.13.4.2  Producing the pre-signature
Compute the point LK  G .
 
NOTE A more efficient way to compute the same result is to first reduce K modulo q , the order of point G .
6.13.4.3  Preparing message for signing
The message is prepared such that M is the message to be signed, i.e. MM= , and M is empty.
2 2 1
6.13.4.4  Computing the witness
Let R be the encoding of L as t octets, following the same steps as in encoding Y : The y -coordinate in the
range 0yp is encoded as a little-endian string of t octets. The most significant bit of the final octet is
always zero. To form the encoding of the point KG , copy the least significant bit of the x -coordinate to
 
 
the most significant bit of the final octet. The result is the witness R .
6.13.4.5  Computing the assignment
The signing entity computes the 2t octet string HRYM and computes T as the reduction modulo q

of the negative of the resulting little-endian integer, i.e. TH RY M mod q.

© ISO/IEC 2026 – All rights reserved
ISO/IEC 14888-3:2018/FDAM 1:2026(en)
Let T 1 .
6.13.4.6  Computing the second part of the signature
Compute SKTX mod q .

The signature is RS,' where S ' is the little-endian encoding of S in t octets.

For Ed25519, the three most significant bits of the final octet are always zero; for Ed448, the 10 most
significant bits of the final two octets are always zero.
6.13.4.7  Constructing the appendix

The appendix will be the concatenation of RS, and an optional text field, text.

6.13.4.8  Constructing the signed message
A signed message is the concatenation of the message, M , and the appendix, i.e. M ||((R,S′),text).
6.13.5   Verification process
6.13.5.1  General
The verifying entity acquires the necessary data items required for the verification process.
6.13.5.2   Retrieving the witness and the verification key
′
The verifier retrieves the witness R and the second part of the signature S from the appendix. The verifier
′
decodes the verification key Y to a point Y on the twisted Edwards curve, decodes R to a point L on the
twisted Edwards curve, and decodes S′ to an integer 0Sq ; if any of the conditions are violated or one of
the decodings fail, the signature shall be rejected.
6.13.5.3   Preparing message for verification
The verifier retrieves M from the signed message and divides the message into two parts M and M such
1 2
that MM= and M is empty.
2 1
6.13.5.4  Retrieving the assignment
The input to the assignment function is computed as in 6.13.4.5 by TT ,,TH1  RY' Mqmod ,
 
again interpreting the hash digest as a little-endian integer of 2t octets and reducing it modulo q .
6.13.5.5  Verifying the signature
The inputs to this stage are system parameters a, d defining the curve and base point G, Edwards curve
point Y decoded from the verificat
...


ISO/IEC 14888-3:2018/FDAMFDAmd 1:2026(en)
ISO/IEC JTC 1/SC 27/WG 2
Secretariat: DIN
Date: 2026-08-05-02
IT Security techniques — Digital signatures with appendix —
Part 3:
Discrete logarithm based mechanisms
AMENDMENT 1
Techniques de sécurité IT — Signatures numériques avec appendice —
Partie 3: Mécanismes basés sur un logarithme discret
AMENDEMENT 1
FDIS stage
© ISO/IEC 2026
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication
may be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying,
or posting on the internet or an intranet, without prior written permission. Permission can be requested from either ISO
at the address below or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: + 41 22 749 01 11
EmailE-mail: copyright@iso.org
Website: www.iso.org
Published in Switzerland
© ISO/IEC 2026 – All rights reserved
ii
ISO/IEC 14888-3:2018/FDAMFDAmd 1:2026(en)
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are members
of ISO or IEC participate in the development of International Standards through technical committees
established by the respective organization to deal with particular fields of technical activity. ISO and IEC
technical committees collaborate in fields of mutual interest. Other international organizations, governmental
and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types of
document should be noted. This document was drafted in accordance with the editorial rules of the ISO/IEC
Directives, Part 2 (see www.iso.org/directives or www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the use of
(a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any claimed
patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not received
notice of (a) patent(s) which may be required to implement this document. However, implementers are
cautioned that this may not represent the latest information, which may be obtained from the patent database
available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall not be held responsible for
identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 27, Information security, cyber security, and privacy protection.
A list of all parts in the ISO/IEC 14888 series can be found on the ISO and IEC websites.
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www.iso.org/members.html and www.iec.ch/national-
committees.
© ISO/IEC 2026 – All rights reserved
iii
ISO/IEC 14888-3:2018/FDAM 1:2026(en)
IT Security techniques — Digital signatures with appendix —
Part 3:
Discrete logarithm based mechanisms
AMENDMENT 1
Introduction
After Note 4, replace the paragraph with the following text:
This document includes 15 mechanisms: two of which (DSA and Pointcheval/Vaudenay algorithm) were in
ISO/IEC 14888-3:1998, three of which (EC-DSA, EC-KCDSA, and EC-GDSA) were from ISO/IEC 15946-2:2002,
three of which (KCDSA, IBS-1 and IBS-2) were added in ISO/IEC 14888-3:2006, four of which (SDSA, EC-RDSA,
EC-SDSA and EC-FSDSA) were added in ISO/IEC 14888-3:2006/Amd 1:2010, two of which (SM2 and Chinese
IBS) were added in ISO/IEC 14888-3:2018 and one of which (EdDSA) is added in this document.
Reword Note 5 as follows:
The mechanisms of EC-DSA, EC-GDSA., EC-RDSA and EC-FSDSA maycan be vulnerable to a key substitution
[10 ]
attack [. ]. The attack is realized if an adversary can find two distinct public keys and one signature such that
the signature is valid for both public keys. There are several approaches to avoiding this attack and its possible
impact on the security of a cryptographic system. For example, the public key corresponding to the private
signing key can be added into the message to be signed. EdDSA includes this protection in its design.

Clause 2, Normative references
Add the following:
ISO/IEC 29192-5, Information technology — Security techniques — Lightweight cryptography: — Part 5: Hash-
functions
Clause3Clause 3, Terms and definitions
Insert the following definition after 3.6.:
3.7
complete twisted Edwards curve group
cyclic group (3.2) defined on the points of a complete twisted Edwards curve over a finite field
Note 1 to entry : Let 𝐹𝐹 = GF(𝑟𝑟) be a finite field where r is an odd prime. Let a and 𝑑𝑑 be distinct non-zero elements of F
2 2 2 2
such that a is a square in F and 𝑑𝑑 is a non-square in F. Then the affine curve 𝑎𝑎𝑥𝑥 +𝑦𝑦 = 1+𝑑𝑑𝑥𝑥 𝑦𝑦 is a complete twisted
Edwards curve defined over F. The set E of points of this curve consists of a collection of certain affine points from 𝐹𝐹×𝐹𝐹,
© ISO/IEC 2025 – All rights reserved

namely those that satisfy the curve equation. Let “+” denote the binary operation known as “Edwards-curve addition”,
defined for all affine points of E by
.
(𝑥𝑥 ,𝑦𝑦 )+(𝑥𝑥 ,𝑦𝑦 ) = ((𝑥𝑥𝑦𝑦 +𝑥𝑥𝑦𝑦 )/(1+𝑑𝑑𝑥𝑥𝑥𝑥𝑦𝑦𝑦𝑦 ),(𝑦𝑦𝑦𝑦 −𝑎𝑎𝑥𝑥𝑥𝑥 )/(1−𝑑𝑑𝑥𝑥𝑥𝑥𝑦𝑦𝑦𝑦 )).
1 1 2 2 1 2 2 1 1 2 1 2 1 2 1 2 1 2 1 2
The identity element for “+” is .(0,1). The set E together with the binary operation “+” forms a finite
commutative group E that is the complete twisted Edwards curve group for this curve.

Clause 4, Symbols and abbreviated terms
Add the following symbols/abbreviated terms:
𝑎𝑎,𝑑𝑑 twisted Edwards curve coefficients
EdDSA Edwards curve Digital Signature Algorithm

Replace the definition of E with the following:
E an elliptic curve defined by two elliptic curve coefficients, 𝑎𝑎 and 𝑎𝑎 , or a twisted Edwards curve
1 2
defined by two curve coefficients a and d

Replace the definition of E with the following:
∗
a finite commutative group; for the mechanisms based on a multiplicative group, the elements of E are in 𝑍𝑍 ;
𝑝𝑝
for the mechanisms based on an additive group of elliptic curve points, the elements of E are the points on an
elliptic curve E over GF(r) or the points on the twisted Edwards curve E over GF(r)
E
a finite commutative group; for the mechanisms based on a multiplicative group, the elements of E
∗
are in 𝑍𝑍 ; for the mechanisms based on an additive group of elliptic curve points, the elements of E
𝑝𝑝
are the points on an elliptic curve E over GF(r) or the points on the twisted Edwards curve E over
GF(r)
Replace the definition of #E with the following:
the cardinality of E; for the mechanisms based on a multiplicative group Z *, #E is p − 1; for the mechanisms
p
based on an additive group of elliptic curve points, #E is one more than the number of points on the elliptic
curve E over GF(r) [including 0 (the point at infinity)]; for the mechanisms based on twisted Edwards curve
E
points, #E is the number of points on the twisted Edwards curve over GF(r)

#E the cardinality of E; for the mechanisms based on a multiplicative group Z *, #E is p − 1; for the
p
mechanisms based on an additive group of elliptic curve points, #E is one more than the number of
points on the elliptic curve E over GF(r) [including 0 (the point at infinity)]; for the mechanisms
E
© ISO/IEC 2026 – All rights reserved
ISO/IEC 14888-3:2018/FDAMFDAmd 1:2026(en)
based on twisted Edwards curve points, #E is the number of points on the twisted Edwards curve 𝐸𝐸
over GF(r)
5.2.2
At the end of Note 2, add the text:
Mechanisms can also permit a larger range for 𝐾𝐾 or specify some algebraic format of .𝐾𝐾.

5.3.5
Add the following text at the end of the subclause:
For EdDSA the verification mechanism is specified in 6.13.

6.1
Replace the first paragraph with the following:
Clause 6 specifies twelve certificate-based mechanisms. These make use of arithmetic in the multiplicative
group Z *, the additive group of elliptic curve points, or the additive group of points on twisted Edwards
p
curves. The mechanisms using arithmetic in the multiplicative group Z *, are the Digital Signature Algorithm
p
(DSA), the Korean Certificate-based Digital Signature Algorithm (KCDSA), the Pointcheval/Vaudenay
algorithm, and the Schnorr Digital Signature Algorithm (SDSA). The mechanisms using arithmetic in the
additive group of elliptic curve points are the Elliptic Curve DSA (EC-DSA), the Elliptic Curve KCDSA (EC-
KCDSA), the Elliptic Curve German Digital Signature Algorithm (EC-GDSA), the Elliptic Curve Russian Digital
Signature Algorithm (EC-RDSA), the Elliptic Curve Schnorr Digital Signature Algorithm (EC-SDSA), the Elliptic
Curve Full Schnorr Digital Signature Algorithm (EC-FSDSA), the SM2 algorithm, and the Edwards-curve Digital
Signature Algorithm (EdDSA).
At the end of the second paragraph insert the text:
The curves Ed25519 and Ed448 for EdDSA are specified in 6.13.

6.3.2
Replace the penultimate paragraph (starting "Three choices") with the following.:
The pair (α,β) for KCDSA shall be chosen in accordance with the chosen security level, as shown in Table 1 in
5.1.3.1. Typical examples are (2 048, 224) and (3 072, 256).
The hash-function h shall be one of the approved hash-functions from ISO/IEC 10118-3 and ISO/IEC 29192-
5. The security strength γ of the hash-function h shall meet or exceed the security strength associated with the
pair (α,β).
© ISO/IEC 2026 – All rights reserved
6.5.2
Replace the paragraph under the listing (starting "Four choices") with the following.:
Three choices for α are permitted in SDSA, namely 1 024, 2 048, and 3 072. The values of γ and β shall be
selected in accordance with the value of α, as specified in Table 1 in 5.1.3.1, such that γ ≥ β. The hash-function
h shall be one of the approved hash-functions from ISO/IEC 10118-3, and its security strength shall meet or
exceed the security strength associated with the pair (α,β).

6.6.1
In the second paragraph, replace the last sentence "The hash-function h . 10118-3" with the following.
The hash function h shall be one of SHA-224, SHA-512/224, SHA3-224, SHA-256, SHA-512/256, SHA3-256,
SHAKE-128 (d=256 bits), SHA-384, SHA3-384, SHA-512, SHA3-512, and SHAKE-256 (d=512 bits) specified in
ISO/IEC 10118-3. The security level γ shall meet or exceed the level associated with the parameter α (see
Table 1 in 5.1.3.1).
6.12.5.7
Add the following text after 6.12.5.7:
6.13  EdDSA
6.13.1  General
EdDSA (Edwards Curve Digital Signature Algorithm) is a signature mechanism with verification key Y′ equal
to the encoding of 𝑌𝑌 = [𝑋𝑋]𝐺𝐺, where 𝐺𝐺 is a specified point on a twisted Edwards curve and 𝑋𝑋 is a multiple of 8.
The parameter 𝐷𝐷 is equal to 1. The message is prepared such that 𝑀𝑀 is empty and 𝑀𝑀 =𝑀𝑀, the message to be
1 2
signed. The witness 𝑅𝑅 is computed as the encoding of 𝐿𝐿 = [𝐾𝐾]𝐺𝐺 for randomizer 𝐾𝐾.
The coefficients (𝐴𝐴,𝐵𝐵,𝐶𝐶) of the EdDSA signature formula are set as
(𝐴𝐴,𝐵𝐵,𝐶𝐶) = (𝑇𝑇 ,𝑇𝑇 ,𝑆𝑆),
1 2
′
where 𝑇𝑇 = (𝑇𝑇 ,𝑇𝑇 ) = (−1,−𝐻𝐻(𝑅𝑅∥𝑌𝑌 ∥𝑀𝑀)) and H is the hash function defined in 6.13.2.
1 2
Thus, the signature formula becomes −𝐾𝐾+𝑇𝑇𝑋𝑋+𝑆𝑆 ≡ 0mod𝑞𝑞.
NOTE The mechanism is taken from Reference [47]. The notation here has been changed from Reference [47] to
conform with the notation used in the ISO/IEC 14888 series.
6.13.2  Parameters
Table 2 lists the parameters for Ed25519 and Ed448 which use the complete twisted Edwards curve group
defined by a and d modulo p.
© ISO/IEC 2026 – All rights reserved
ISO/IEC 14888-3:2018/FDAMFDAmd 1:2026(en)
Table 2 — Parameters for Ed25519 and Ed448
Ed25519 Ed448
255 448 224
p
2 −19 2 −2 −1
b 256 456
c 8 4
t 32 57
H′(x) SHA-512(x) SHAKE256(x,114)
H(x) SHA-512(x) SHAKE256(dom4(0,context) || x, 114)
d −121665 / 121666 −39081
a −1 1
For Ed448, dom4(0,context) is the octet string "SigEd448" || octet(0) ||octet(OLEN(context)) || context, where
context is an octet string of at most 255 octets and OLEN(context) denotes its length in octets. "SigEd448" is
in ASCII (8 octets).
The base point 𝐺𝐺 of order 𝑞𝑞 = 2 +27742317777372353535851937790883648493 on Ed25519 has
coordinates (𝑥𝑥,𝑦𝑦) where x is
and y is
The base point 𝐺𝐺 of order q =
2 −13818066809895115352007386748515426880336692474882178609894547503885
on Ed448 has coordinates (𝑥𝑥,𝑦𝑦), where x is
and 𝑦𝑦 is
6.13.3  Generation of signature key and verification key
The signature key of a signing entity is a secretly generated random or pseudo-random bitstring 𝑋𝑋′ of length
𝑏𝑏.
′
The integer 𝑋𝑋, so that 𝑌𝑌 = [𝑋𝑋]𝐺𝐺, is derived from 𝑋𝑋 through hashing and processing.
′ ′ ′
For Ed25519 take 𝐻𝐻 (𝑋𝑋 ) = SHA-512(𝑋𝑋 ), storing the digest in a 64-octet large buffer. Set the lowest three
bits of the first octet to 0. Set the highest bit of the t-th octet to 0. Set the second highest bit of the t-th octet to
1. Interpret the first t octets as a little-endian integer, forming a secret integer 𝑋𝑋.
′ ′ ′
For Ed448 take 𝐻𝐻 (𝑋𝑋 )= SHAKE256(𝑋𝑋 ,114), storing the digest in a 114-octet large buffer. Set the lowest two
bits of the first octet to 0. Set all eight bits of the t-th octet to 0. Set the highest bit of the (t-1)-st octet to 1.
Interpret the first t octets as a little-endian integer, forming a secret integer 𝑋𝑋.
© ISO/IEC 2026 – All rights reserved
′
EdDSA specifies the verification key 𝑌𝑌 as the encoding of the point 𝑌𝑌 = [𝑋𝑋]𝐺𝐺. The 𝑦𝑦-coordinate in the range
0≤𝑦𝑦 <𝑝𝑝 is encoded as a little-endian string of 𝑡𝑡 octets. The most significant bit of the final octet is always
zero. To form the encoding of the point [𝑋𝑋]𝐺𝐺, copy the least significant bit of the 𝑥𝑥-coordinate to the most
significant bit of the final octet. The result is the verification key.
6.13.4  Signature process
6.13.4.1  Producing the randomizer and decoding the secret integer
′
The signing entity computes the pseudo-random integer 𝐾𝐾 using the private signing key 𝑋𝑋 and the message
𝑀𝑀 using the following two steps. The first step also recovers the secret integer 𝑋𝑋 used in the signature
equation.
′ ′
— Compute ℎ =𝐻𝐻 (𝑋𝑋 ) of 2𝑡𝑡 octets. Construct the secret integer 𝑋𝑋 from the first half of 𝐻𝐻 as in 6.13.3. Let 𝑠𝑠 denote

the second half of the hash digest, ℎ[𝑡𝑡],.,ℎ[2𝑡𝑡−1].
— Compute 𝐻𝐻(𝑠𝑠∥𝑀𝑀) of 2𝑡𝑡 octets and interpret the digest as a little-endian integer 𝐾𝐾.

6.13.4.2  Producing the pre-signature
Compute the point 𝐿𝐿 = [𝐾𝐾]𝐺𝐺.
NOTE A more efficient way to compute the same result is to first reduce 𝐾𝐾 modulo 𝑞𝑞, the order of point 𝐺𝐺.
6.13.4.3  Preparing message for signing
The message is prepared such that 𝑀𝑀 is the message to be signed, i.e. 𝑀𝑀 =𝑀𝑀, and 𝑀𝑀 is empty.
2 2 1
6.13.4.4  Computing the witness
Let 𝑅𝑅 be the encoding of L as 𝑡𝑡 octets, following the same steps as in encoding 𝑌𝑌: The 𝑦𝑦-coordinate in the range
0≤𝑦𝑦 <𝑝𝑝 is encoded as a little-endian string of t octets. The most significant bit of the final octet is always
zero. To form the encoding of the point [𝐾𝐾]𝐺𝐺, copy the least significant bit of the 𝑥𝑥-coordinate to the most
significant bit of the final octet. The result is the witness 𝑅𝑅.
6.13.4.5  Computing the assignment
′
The signing entity computes the 2𝑡𝑡 octet string 𝐻𝐻(𝑅𝑅∥𝑌𝑌 ∥𝑀𝑀) and computes 𝑇𝑇 as the reduction modulo 𝑞𝑞 of
′
the negative of the resulting little-endian integer, i.e. 𝑇𝑇 =−𝐻𝐻(𝑅𝑅∥𝑌𝑌 ∥𝑀𝑀) mod q.
Let 𝑇𝑇 =−1.
6.13.4.6  Computing the second part of the signature
Compute 𝑆𝑆 = (𝐾𝐾−𝑇𝑇 ⋅𝑋𝑋) mod 𝑞𝑞.
The signature is (𝑅𝑅,𝑆𝑆′) where 𝑆𝑆′ is the little-endian encoding of 𝑆𝑆 in 𝑡𝑡 octets.
For Ed25519, the three most significant bits of the final octet are always zero; for Ed448, the 10 most
significant bits of the final two octets are always zero.
6.13.4.7  Constructing the appendix
′
The appendix will be the concatenation of (𝑅𝑅,𝑆𝑆 ) and an optional text field, text.
© ISO/IEC 2026 – All rights reserved
ISO/IEC 14888-3:2018/FDAMFDAmd 1:2026(en)
6.13.4.8  Constructing the signed message
A signed message is the concatenation of the message, 𝑀𝑀, and the appendix, i.e. M ||((R,S′),text).
6.13.5  Verification process
6.13.5.1  General
The verifying entity acquires the necessary data items required for the verification process.
6.13.5.2  Retrieving the witness and the verification key
′
The verifier retrieves the witness 𝑅𝑅 and the second part of the signature 𝑆𝑆 from the appendix. The verifier
′
decodes the verification key 𝑌𝑌 to a point 𝑌𝑌 on the twisted Edwards curve, decodes 𝑅𝑅 to a point L on the twisted
′
Edwards curve, and decodes 𝑆𝑆 to an integer 0≤𝑆𝑆 <𝑞𝑞; if any of the conditions are violated or one of the
decodings fail, the signature shall be rejected.
6.13.5.3  Preparing message for verification
The verifier retrieves 𝑀𝑀 from the signed message and divides the message into two parts 𝑀𝑀 and 𝑀𝑀 such that
1 2
𝑀𝑀 =𝑀𝑀 and 𝑀𝑀 is empty.
2 1
6.13.5.4  Retrieving the assignment
The input to the assignment function is computed as in 6.13.4.5 by 𝑇𝑇 = (𝑇𝑇 ,𝑇𝑇 )= (−1,−𝐻𝐻(𝑅𝑅∥𝑌𝑌′∥
1 2
𝑀𝑀) mod 𝑞𝑞), again interpreting the hash digest as a little-endian integer of 2𝑡𝑡 octets and reducing it modulo 𝑞𝑞.
6.13.5.5  Verifying the signature
The inputs to this stage are system parameters a, d defining the curve and base point G, Edwards curve point
′
𝑌𝑌 decoded from the verification key 𝑌𝑌 , assignment 𝑇𝑇 = (𝑇𝑇 ,𝑇𝑇 ) from 6.13.5.4 and decoded integer 𝑆𝑆
1 2
corresponding to the second part of the signature 𝑆𝑆′ from 6.13.5.2.
The verifier checks the group equation [𝑐𝑐][𝑆𝑆]𝐺𝐺 = [𝑐𝑐]𝐿𝐿−[𝑐𝑐][𝑇𝑇 ]𝑌𝑌.
If this equality holds, then the signature is verified else the signature shall be rejected.
NOTE It is sufficient, but not required, to instead check [𝑆𝑆]𝐺𝐺 =𝐿𝐿−[𝑇𝑇 ]𝑌𝑌.
Annex A
Replace the entirety of Annex A with the following:
Annex AT
...