Abstract
ISO has been working on a multi-part authentication mechanisms standard for some years. The first part, ISO/IEC 9798-1 [15], has recently been published. Parts two and three (9798-2, [18] and 9798-3, [17]), covering authentication mechanisms based on symmetric and asymmetric cryptographic techniques respectively, are now moving towards DIS (Draft International Standard) and full International Standard status respectively. This paper is concerned with authentication mechanisms based on asymmetric cryptography; more specifically it contrasts two important authentication mechanisms from the latest version of 9798-3 and from CCITT Recommendation X.509-1988 [9], and briefly illustrates certain known attacks against this type of mechanism. A new potential security problem is then described, to which many published mechanisms appear to be prone. Possible solutions to this problem are discussed, together with potential ramifications on existing standardisation activity.
Get full access to this article
View all access options for this article.
