General Information

Abstract

Status
Not Published
Current Stage
6000 - International Standard under publication
Start Date
10-Sep-2026
Completion Date
19-Sep-2026

Buy Documents

Draft

ISO/IEC 20009-4:2017/PRF Amd 1 - Information technology — Security techniques — Anonymous entity authentication — Part 4: Mechanisms based on weak secrets — Amendment 1

Release Date:12-Aug-2026
English language (7 pages)
sale 15% off
sale 15% off
Draft

REDLINE ISO/IEC 20009-4:2017/PRF Amd 1 - Information technology — Security techniques — Anonymous entity authentication — Part 4: Mechanisms based on weak secrets — Amendment 1

Release Date:12-Aug-2026
English language (7 pages)
sale 15% off
sale 15% off

Overview

ISO/IEC 20009-4:2017/Amd 1:2026 is an essential international standard from ISO and IEC, focused on Information technology - Security techniques for anonymous entity authentication. This amendment specifically updates Part 4, which addresses mechanisms based on weak secrets, and introduces enhanced specifications, new references, and additional mechanisms to bolster privacy and security in authentication processes. Managed by ISO/IEC JTC 1/SC 27, this amendment strengthens approaches to password-based and group-based anonymous authentication, offering practical solutions for ensuring user privacy in digital environments.

Key Topics

  • Anonymous Entity Authentication: The standard outlines protocols that allow users to prove group membership or identity anonymously, particularly when credentials are derived from passwords or similar weak secrets.
  • Mechanisms Based on Weak Secrets: Focuses on authentication approaches using weak secrets, such as user passwords, that do not rely on strong cryptographic keys.
  • Credential Management: Details on password file structuring, user registration, user revocation, and credential revocation using dynamic accumulators.
  • Interoperability and Security Enhancements: Amendment 1 adds normative references to other ISO standards for digital signatures and encryption algorithms to ensure cryptographic robustness.
  • Introduction of New Mechanisms and Procedures: Addition of the ZYHW mechanism, which uses modern signature and hash function techniques, ensuring that credentials and their revocation can be handled securely.
  • Mutual and Unilateral Authentication: Provides clear guidelines on mutual authentication (server and user) or simplified configurations with only unilateral authentication, accommodating different application needs.
  • User Revocation: Explains advanced user revocation methods, including revocation from all or selected groups as well as management of credential revocation lists (CRLs).

Applications

ISO/IEC 20009-4:2017/Amd 1 is highly applicable in a variety of environments where privacy, anonymity, and secure authentication are paramount. Typical use cases include:

  • Privacy-Preserving Online Services: Websites or digital platforms that require users to authenticate without revealing personal identity information, such as anonymous voting or comment systems.
  • Group-based Access Control: Corporate or shared systems where users must verify group membership without disclosing their unique identities.
  • Secure Password-Authentication Systems: Scenarios where only weak secrets (like user passwords) are available, but robust privacy and revocation capabilities are required.
  • Revocable Anonymous Credentials: Systems that need to revoke user access or group membership efficiently without compromising other users' privacy or credential integrity.
  • Compliance-Driven Sectors: Organizations in healthcare, finance, or government sectors that need to meet stringent privacy standards during digital authentication processes.

Related Standards

To ensure comprehensive security and interoperability, this amendment references and complements several key international standards:

  • ISO/IEC 14888-2: Digital signatures with appendix - Integer factorization based mechanisms.
  • ISO/IEC 14888-3: Digital signatures with appendix - Discrete logarithm-based mechanisms.
  • ISO/IEC 18033-2: Encryption algorithms - Asymmetric ciphers.

For broader context, the ISO/IEC 20009 series covers a range of anonymous entity authentication mechanisms, allowing implementers to choose solutions that best meet their security, privacy, and operational requirements.


By aligning authentication mechanisms with international best practices, ISO/IEC 20009-4:2017/Amd 1 helps organizations develop, update, and maintain systems that protect user anonymity, support secure credential management, and ensure effective user group control, even where only weak secrets are available.

Relations

Effective Date
28-Oct-2023

Buy Documents

Draft

ISO/IEC 20009-4:2017/PRF Amd 1 - Information technology — Security techniques — Anonymous entity authentication — Part 4: Mechanisms based on weak secrets — Amendment 1

Release Date:12-Aug-2026
English language (7 pages)
sale 15% off
sale 15% off
Draft

REDLINE ISO/IEC 20009-4:2017/PRF Amd 1 - Information technology — Security techniques — Anonymous entity authentication — Part 4: Mechanisms based on weak secrets — Amendment 1

Release Date:12-Aug-2026
English language (7 pages)
sale 15% off
sale 15% off

Get Certified

Connect with accredited certification bodies for this standard

BSI Group

BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

UKAS United Kingdom Verified

Bureau Veritas

Bureau Veritas is a world leader in laboratory testing, inspection and certification services.

COFRAC France Verified

DNV

DNV is an independent assurance and risk management provider.

NA Norway Verified

Sponsored listings

Frequently Asked Questions

ISO/IEC 20009-4:2017/Amd 1 is a draft published by the International Organization for Standardization (ISO). Its full title is "Information technology — Security techniques — Anonymous entity authentication — Part 4: Mechanisms based on weak secrets — Amendment 1". This standard covers: Information technology — Security techniques — Anonymous entity authentication — Part 4: Mechanisms based on weak secrets — Amendment 1

Information technology — Security techniques — Anonymous entity authentication — Part 4: Mechanisms based on weak secrets — Amendment 1

ISO/IEC 20009-4:2017/Amd 1 is classified under the following ICS (International Classification for Standards) categories: 35.030 - IT Security. The ICS classification helps identify the subject area and facilitates finding related standards.

ISO/IEC 20009-4:2017/Amd 1 has the following relationships with other standards: It is inter standard links to ISO/IEC 20009-4:2017. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.

ISO/IEC 20009-4:2017/Amd 1 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


International
Standard
ISO/IEC 20009-4
First edition
Information technology — Security
2017-08
techniques — Anonymous entity
authentication —
AMENDMENT 1
Part 4:
Mechanisms based on weak secrets
AMENDMENT 1
Technologies de l'information — Techniques de sécurité —
Authentification d'entité anonyme —
Partie 4: Mécanismes basés sur des secrets faibles
AMENDEMENT 1
PROOF/ÉPREUVE
Reference number
ISO/IEC 20009-4/Amd. 1:2026(en) © ISO/IEC 2026

ISO/IEC 20009-4/Amd. 1:2026(en)
© ISO/IEC 2026
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
PROOF/ÉPREUVE
© ISO/IEC 2026 – All rights reserved
ii
ISO/IEC 20009-4/Amd. 1:2026(en)
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical activity.
ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations,
governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of document should be noted. This document was drafted in accordance with the editorial rules of the ISO/
IEC Directives, Part 2 (see www.iso.org/directives or www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the
use of (a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any
claimed patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had
received notice of (a) patent(s) which may be required to implement this document. However, implementers
are cautioned that this may not represent the latest information, which may be obtained from the patent
database available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall not be held
responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 27, Information security, cybersecurity and privacy protection.
A list of all parts in the ISO/IEC 20009 series can be found on the ISO and IEC websites.
Any feedback or questions on this document should be directed to the user’s national standards
body. A complete listing of these bodies can be found at www.iso.org/members.html and
www.iec.ch/national-committees.
PROOF/ÉPREUVE
© ISO/IEC 2026 – All rights reserved
iii
ISO/IEC 20009-4/Amd. 1:2026(en)
Information technology — Security techniques — Anonymous
entity authentication —
Part 4:
Mechanisms based on weak secrets
AMENDMENT 1
Clause 2
Add the following normative references:
ISO/IEC 14888-2, Information technology — Security techniques — Digital signatures with appendix —
Part 2: Integer factorization based mechanisms
ISO/IEC 14888-3, IT Security techniques — Digital signatures with appendix — Part 3: Discrete logarithm
based mechanisms
ISO/IEC 18033-2, Information technology — Security techniques — Encryption algorithms — Part 2:
Asymmetric ciphers
4.2
Replace the text in this subclause as follows:
EC2OSP elliptic curve point to octet string conversion primitive, which shall be equivalent to
the specified conversion primitive EC2OSP (P, compressed) for a point P over an elliptic
E
curve E in accordance with ISO/IEC 18033-2
FE2OSP field element to octet string conversion primitive, which shall be as specified in ISO/IEC
18033-2
BS2IP bit string to integer conversion primitive, which shall be as specified in ISO/IEC 18033-2
GE2OSP cyclic group element to octet string conversion primitive. If the mechanism is defined
over a finite field, it is the same as FE2OSP. If it is defined over an elliptic curve, it is the
same as EC2OSP.
5.3
Replace the paragraph beginning with “Setup” as follows:
Setup: Given a security parameter secparam, the server generates and maintains a tuple
params,PWF  , where params denotes public system parameters and PWF is a password file,
initially set empty, that is kept private. The password file PWF consists of a set of ordered pairs,
Ip, vd , one for each member of the user group, where I and pvd are the distinguishing identifier
U U
UU
and password verification data for the user, U, respectively. params will be the common input to the
PROOF/ÉPREUVE
© ISO/IEC 2026 – All rights reserved
ISO/IEC 20009-4/Amd. 1:2026(en)
other operations of the mechanism, but for simplicity, it is deliberately omitted from the specifications
of inputs of the operations.
Replace the paragraph beginning with “User registration” as follows:
User registration: This process can be non-interactive if PWF is empty. Otherwise, it should be
interactive to avoid registering duplicate identifiers. Given a user's distinguishing identifier, I , and a
U
password, pw , from the user and a password file, PWF, from the server, generate password verification
U
data, pvd , and then add Ip, vd to the password file, PWF.
U
UU
Replace the paragraph beginning with “User revocation” as follows:
User revocation: Given a user identity, I , and a password file, PWF, the server removes Ip, vd
U
UU
from the password file, PWF, and then update the pre-computed values, if any.
Remove the paragraph beginning with “NOTE 1”.
Replace the paragraph beginning with “NOTE 2” as follows:
NOTE The anonymous authentication operation is specified to include mutual authentication and key
exchange. Depending on the application, it can be minimally specified to include only unilateral authenti-
cation from a user to a server or a server authenticates only that the user belongs to a certain user group,
without the opposite direction of authentication and key exchange.

5.4
Replace the paragraph beginning with “User registration” as follows:
User registration: This is an interactive process between a user and a server. Given a user's
distinguishing identifier, I , and a password, pw , from the user and the server key, ServK, from the
U U
server, output a password wrapped credential, cred . cred may be stored anywhere accessible to
pw pw
U U
the user, e.g. in a portable storage device or a public directory.
Replace the paragraph beginning with “User revocation” as follows:
User revocation: Given a user's distinguishing identifier, I , and password wrapped credential, cred
U
pw
U
, the server revokes the authentication credential for I and updates CRL (Credential Revocation List)
U
such that CRL = CRL ∪ {cred}, where CRL is the updated CRL and CRL is the old CRL and cred is
new old new old
the original credential contained in cred . CRL is part of params and is initially set empty. The server
pw
U
maintains CRL, and the details depend on each mechanism in 7.
Remove NOTE 1.
Replace NOTE 2 as follows:
NOTE The anonymous authentication operation is specified to include mutual authentication and key
exchange. Depending on the application, it can be minimally specified to include only unilateral authenti-
cation from a user to a server or a server authenticates only that the user belongs to a certain user group,
without authentication from a server to a user and key exchange.

6.2.2
Replace bullet point c) with the following text:
PROOF/ÉPREUVE
© ISO/IEC 2026 – All rights reserved
ISO/IEC 20009-4/Amd. 1:2026(en)
c) U is added to a legitimate user group where the user group is denoted by U.
i
6.2.4
Replace the text as follows:
The SKI mechanism supports two types of user revocation: 1) exclude the user only from some user
groups while leaving the user in the other user groups and in the password file, PWF, 2) exclude the user
from the password file, PWF. In the former case, execute only step b) below and in the latter case execute
both a) and b). A user U can be revoked by the server, S, as follows.
i
a) Remove Ip, vd from the password file PWF.
UU
ii
b) Remove U from user group U, and then execute “Preparation phase for C ” as defined in 6.2.3.3 for
i j
the updated user g
...


ISO/IEC 20009-4:2017/DAMPRF Amd 1:2026(en)
ISO/IEC JTC 1/SC 27
Secretariat: DIN
Date: 2026-608-12
Information technology — Security techniques — Anonymous entity
authentication — —
Part 4:
Mechanisms based on weak secrets —
Amendment
AMENDMENT 1
Technologies de l'information — Techniques de sécurité — Authentification d'entité anonyme —
Partie 4: Mécanismes basés sur des secrets faibles
AMENDEMENT 1
PROOF
ISO/IEC 20009-4:2017(X)/AMD/PRF Amd 1(en)
© ISO/IEC 2026
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication
may be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying,
or posting on the internet or an intranet, without prior written permission. Permission can be requested from either ISO
at the address below or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: + 41 22 749 01 11
EmailE-mail: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii
ISO/IEC 20009-4:2017/DAMPRF Amd 1:2026(en)
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are members
of ISO or IEC participate in the development of International Standards through technical committees
established by the respective organization to deal with particular fields of technical activity. ISO and IEC
technical committees collaborate in fields of mutual interest. Other international organizations, governmental
and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types of
document should be noted. This document was drafted in accordance with the editorial rules of the ISO/IEC
Directives, Part 2 (see www.iso.org/directives or www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the use of
(a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any claimed
patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had received notice
of (a) patent(s) which may be required to implement this document. However, implementers are cautioned
that this may not represent the latest information, which may be obtained from the patent database available
at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall not be held responsible for identifying
any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.
Field Code Changed
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 27, Information security, cybersecurity and privacy protection.
A list of all parts in the ISO/IEC 20009 series can be found on the ISO and IEC websites.
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www.iso.org/members.html and www.iec.ch/national-
Field Code Changed
committees.
© ISO/IEC 2026 – All rights reserved
iii
ISO/IEC 20009-4:2017/DAM 1:2025(en)
Information technology — Security techniques — Anonymous entity
authentication — —
Part 4:
Mechanisms based on weak secrets —
Amendment
AMENDMENT 1
Clause 2
Add the following normative references:
ISO/IEC 14888-2, Information technology — Security techniques — Digital signatures with appendix —
Part 2: Integer factorization based mechanisms
ISO/IEC 14888-3, IT Security techniques — Digital signatures with appendix — Part 3: Discrete logarithm
based mechanisms
ISO/IEC 18033-2, Information technology — Security techniques — Encryption algorithms — Part 2:
Asymmetric ciphers
4.2
Replace the text in this subclause as follows:
EC2OSP elliptic curve point to octet string conversion primitive, which shall be equivalent to the
specified conversion primitive EC2OSPE(P, compressed) for a point P over an elliptic curve
E in accordance with ISO/IEC 18033-2
FE2OSP field element to octet string conversion primitive, which shall be as specified in ISO/IEC
18033-2
BS2IP bit string to integer conversion primitive, which shall be as specified in ISO/IEC 18033-2
GE2OSP cyclic group element to octet string conversion primitive. If the mechanism is defined
over a finite field, it is the same as FE2OSP. If it is defined over an elliptic curve, it is the
same as EC2OSP.
5.3
Replace the paragraph beginning with “Setup” as follows:
Setup: Given a security parameter secparam, the server generates and maintains a tuple 〈𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝,𝑃𝑃𝑃𝑃𝑃𝑃 =
⊥〉, where params denotes public system parameters and PWF is a password file, initially set empty, that
© ISO/IEC 2025 – All rights reserved

ISO/IEC 20009-4:2017(X)/AMD/PRF Amd 1(en)
is kept private. The password file PWF consists of a set of ordered pairs, 〈𝐼𝐼 ,𝑝𝑝𝑝𝑝𝑑𝑑 〉, one for each member
U U
of the user group, where IU and pvdU are the distinguishing identifier and password verification data for
the user, U, respectively. params will be the common input to the other operations of the mechanism, but
for simplicity, it is deliberately omitted from the specifications of inputs of the operations.

Replace the paragraph beginning with “User registration” as follows:
User registration: This process can be non-interactive if PWF is empty. Otherwise, it should be
interactive to avoid registering duplicate identifiers. Given a user's distinguishing identifier, I , and a
U
password, pw , from the user and a password file, PWF, from the server, generate password verification
U
data, pvdU, and then add 〈𝐼𝐼 ,𝑝𝑝𝑝𝑝𝑑𝑑 〉 to the password file, PWF.
U U
Replace the paragraph beginning with “User revocation” as follows:
User revocation: Given a user identity, I , and a password file, PWF, the server removes 〈𝐼𝐼 ,𝑝𝑝𝑝𝑝𝑑𝑑 〉 from
U
U U
the password file, PWF, and then update the pre-computed values, if any.
Remove the paragraph beginning with “NOTE 1”.
Replace the paragraph beginning with “NOTE 2” as follows:
NOTE The anonymous authentication operation is specified to include mutual authentication and key
exchange. Depending on the application, it can be minimally specified to include only unilateral
authentication from a user to a server or a server authenticates only that the user belongs to a certain
user group, without the opposite direction of authentication and key exchange.

NOTE The anonymous authentication operation is specified to include mutual authentication and key
exchange. Depending on the application, it can be minimally specified to include only unilateral
authentication from a user to a server or a server authenticates only that the user belongs to a certain
user group, without the opposite direction of authentication and key exchange.

5.4
Replace the paragraph beginning with “User registration” as follows:
User registration: This is an interactive process between a user and a server. Given a user's
distinguishing identifier, I , and a password, pw , from the user and the server key, ServK, from the server,
U U
output a password wrapped credential, 𝑐𝑐𝑝𝑝𝑐𝑐𝑑𝑑 . 𝑐𝑐𝑝𝑝𝑐𝑐𝑑𝑑 may be stored anywhere accessible to the user,
𝑝𝑝𝑤𝑤 𝑝𝑝𝑤𝑤
U U
e.g. in a portable storage device or a public directory.
Replace the paragraph beginning with “User revocation” as follows:
User revocation: Given a user's distinguishing identifier, I , and password wrapped credential, 𝑐𝑐𝑝𝑝𝑐𝑐𝑑𝑑 ,
U
𝑝𝑝𝑤𝑤
U
the server revokes the authentication credential for IU and updates CRL (Credential Revocation List) such
that CRL = CRL ∪ {cred}, where CRL is the updated CRL and CRL is the old CRL and cred is the
new old new old
original credential contained in 𝑐𝑐𝑝𝑝𝑐𝑐𝑑𝑑 . CRL is part of params and is initially set empty. The server
𝑝𝑝𝑤𝑤
U
maintains CRL, and the details depend on each mechanism in 7.
Remove NOTE 1.
ISO/IEC 20009-4:2017/DAMPRF Amd 1:2025(en)
Replace the paragraph beginning with “NOTE 2” as follows:
NOTE The anonymous authentication operation is specified to include mutual authentication and key
exchange. Depending on the application, it can be minimally specified to include only unilateral
authentication from a user to a server or a server authenticates only that the user belongs to a certain
user group, without authentication from a server to a user and key exchange.

The anonymous authentication operation is specified to include mutual authentication
and key exchange. Depending on the application, it can be minimally specified to include only unilateral
authentication from a user to a server or a server authenticates only that the user belongs to a certain
user group, without authentication from a server to a user and key exchange.

6.2.2
Replace bullet point c) with the following text:
c) Ui is added to a legitimate user group where the user group is denoted by U.
c) Ui is added to a legitimate user group where the user group is denoted by U.

6.2.4
Replace the text as follows:
The SKI mechanism supports two types of user revocation: 1) exclude the user only from some user
groups while leaving the user in the other user groups and in the password file, PWF, 2) exclude the user
from the password file, PWF. In the former case, execute only step b) below and in the latter case execute
both a) and b). A user U can be revoked by the server, S, as follows.
i
a) Remove from the password file PWF.
b) Remove U from user group U, and then execute “Preparation phase for C ” as defined in 6.2.3.3 for the
i j
updated user groups that exclude the revoked user.
The SKI mechanism supports two types of user revocation: 1) exclude the user only from some user
groups while leaving the user in the other user grou
...