ISO/IEC DIS 11770-4

Information security — Key management — Part 4: Mechanisms based on weak secrets ISO/IEC DIS 11770-4

General information

40.60   Close of voting   Feb 27, 2026

ISO/IEC

ISO/IEC JTC 1/SC 27 Information security, cybersecurity and privacy protection

International Standard

35.030   IT Security

Scope

ISO/IEC 11770-4:2017 defines key establishment mechanisms based on weak secrets, i.e. secrets that can be readily memorized by a human, and hence, secrets that will be chosen from a relatively small set of possibilities. It specifies cryptographic techniques specifically designed to establish one or more secret keys based on a weak secret derived from a memorized password, while preventing offline brute-force attacks associated with the weak secret. ISO/IEC 11770-4:2017 is not applicable to the following aspects of key management:
- life-cycle management of weak secrets, strong secrets, and established secret keys;
- mechanisms to store, archive, delete, destroy, etc. weak secrets, strong secrets, and established secret keys.

Life cycle

NOW

IN_DEVELOPMENT
ISO/IEC DIS 11770-4
40.60 Close of voting
Feb 27, 2026




Access Genorma App Everywhere

Get fast and easy access to top European and International standards (EN, ISO, IEC) via your mobile phone, tablet or the web.