ISO/IEC 11770-4:2017/AMD2:2021 PDF | Request Standard
Historical

ISO/IEC 11770-4:2017/AMD2:2021

Information technology - Security techniques - Key management - Part 4: Mechanisms based on weak secrets - Amendment 2: Leakage-resilient password-authenticated key agreement with additional stored secrets

Standard by IEC, 2021-02-02

Available Formats:

  • Availability: Immediate Download
  • Language: English
  • License Type: Single User
  • Updates: Not Included
  • Availability: Request Quote
  • Language: English
  • License Type: Enterprise / Multi User
  • Updates: Included

About This Item

Legal Notices*

ISO/IEC 11770-4:2017/AMD2:2021 is a focused amendment to the key management series that updates ISO/IEC 11770-4:2017/AMD2:2021 for mechanisms based on weak secrets. Based on the official title, it addresses leakage-resilient password-authenticated key agreement with additional stored secrets, which is relevant where authentication and key establishment must remain robust even under constrained or exposed secret conditions. For teams performing technical review, risk management, or compliance workflows, it provides a targeted reference connected to the parent document and its security model.

What is ISO/IEC 11770-4:2017/AMD2:2021?

This amendment modifies the parent reference ISO/IEC 11770-4 and is part of the broader ISO/IEC 11770 key management series. Its technical purpose is to support a specific mechanism for password-authenticated key agreement that is designed to be more resilient to leakage when additional stored secrets are involved. In practice, it is relevant when evaluating authentication and key management methods for documented evaluation, technical validation, and conformity assessment preparation. The document should be read as a supporting reference that refines the parent standard rather than a standalone implementation guide.

Applications of ISO/IEC 11770-4:2017/AMD2:2021

Organizations may use this amendment when reviewing security architectures that rely on password-based access combined with stored secret material, particularly in systems where resistance to secret exposure is an operational concern. It can be useful in engineering documentation, procurement review, and laboratory evaluation of key agreement mechanisms for software platforms, embedded systems, or networked services. It also supports internal technical assessment where teams need to align security design choices with a defined compliance reference and maintain consistency across testing workflows and product evaluation activities.

Why is ISO/IEC 11770-4:2017/AMD2:2021 important?

This amendment matters because it helps organizations assess a security mechanism in a structured way, especially when password-based authentication must be paired with additional stored secrets and the risk of leakage needs to be considered. For compliance teams and engineers, it can improve technical consistency, reduce ambiguity in validation work, and support procurement decisions that depend on a clear security baseline. It is also useful for conformity assessment preparation, where documented evaluation and controlled interpretation of key management requirements are important to quality workflows and risk reduction.

  • Supporting amendment to the ISO/IEC 11770 key management series
  • Focuses on leakage-resilient password-authenticated key agreement
  • Relevant to systems using additional stored secrets in security design
  • Useful for technical review, testing workflows, and compliance workflows
  • Helps align engineering documentation with a defined security reference
SKU: b132b18636a7

  • Publication Date: 2021-02-02
  • Standard Status: Amendment
  • Publisher: IEC
  • Edition: 2

Please request information about the document. Contact Page

Online Standart App

Need This Standard?

Need This Standard?

Summarize with AI

ChatGPT Perplexity Google AI Claude Grok

Online Standart Disclaimer

OnlineStandart.com is an authorized reseller of international standards, operating through partnerships with authorized distributors. We do not own the copyrights or trademarks of the standards we sell, including but not limited to those of API, ASHRAE, BSI, SAE, ASTM, IEEE, IEC, ASME, ISO, and others.

All product names, logos, and brands are the property of their respective owners and are used for identification purposes only; their use does not imply endorsement. OnlineStandart.com is not affiliated with or endorsed by any standards development organization unless explicitly stated. The content of this document is for informational purposes only and is intended to promote our licensed reselling services.

Online Standart does not host, distribute, or link to free, unlicensed, or uncertified copies of copyrighted standards. Every document we deliver is a licensed copy obtained through authorized channels and supplied with full licensing documentation. The “Free PDF Download” option on our product pages refers to this free informational document — never to a free copy of any standard.