ISO-9735-6-2002.pdf

上传人:来看看 文档编号:3780115 上传时间:2019-09-23 格式:PDF 页数:36 大小:418.95KB
返回 下载 相关 举报
ISO-9735-6-2002.pdf_第1页
第1页 / 共36页
ISO-9735-6-2002.pdf_第2页
第2页 / 共36页
ISO-9735-6-2002.pdf_第3页
第3页 / 共36页
ISO-9735-6-2002.pdf_第4页
第4页 / 共36页
ISO-9735-6-2002.pdf_第5页
第5页 / 共36页
亲,该文档总共36页,到这儿已超出免费预览范围,如果喜欢就下载吧!
资源描述

《ISO-9735-6-2002.pdf》由会员分享,可在线阅读,更多相关《ISO-9735-6-2002.pdf(36页珍藏版)》请在三一文库上搜索。

1、 Reference number ISO 9735-6:2002(E) ISO 2002 INTERNATIONAL STANDARD ISO 9735-6 Second edition 2002-07-01 Electronic data interchange for administration, commerce and transport (EDIFACT) Application level syntax rules (Syntax version number: 4, Syntax release number: 1) Part 6: Secure authentication

2、 and acknowledgement message (message type AUTACK) change de donnes informatis pour ladministration, le commerce et le transport (EDIFACT) Rgles de syntaxe au niveau de lapplication (numro de version de syntaxe: 4, numro ddition de syntaxe: 1) Partie 6: Message scuris pour lauthentification et accus

3、 de rception (type de message AUTACK) Copyright International Organization for Standardization Provided by IHS under license with ISO Licensee=Qatar Petroleum/5943408001 Not for Resale, 04/12/2007 03:04:47 MDTNo reproduction or networking permitted without license from IHS -,-,- ISO 9735-6:2002(E) P

4、DF disclaimer This PDF file may contain embedded typefaces. In accordance with Adobes licensing policy, this file may be printed or viewed but shall not be edited unless the typefaces which are embedded are licensed to and installed on the computer performing the editing. In downloading this file, p

5、arties accept therein the responsibility of not infringing Adobes licensing policy. The ISO Central Secretariat accepts no liability in this area. Adobe is a trademark of Adobe Systems Incorporated. Details of the software products used to create this PDF file can be found in the General Info relati

6、ve to the file; the PDF-creation parameters were optimized for printing. Every care has been taken to ensure that the file is suitable for use by ISO member bodies. In the unlikely event that a problem relating to it is found, please inform the Central Secretariat at the address given below. ISO 200

7、2 All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and microfilm, without permission in writing from either ISO at the address below or ISOs member body in the coun

8、try of the requester. ISO copyright office Case postale 56 CH-1211 Geneva 20 Tel. + 41 22 749 01 11 Fax + 41 22 749 09 47 E-mail copyrightiso.ch Web www.iso.ch Printed in Switzerland ii ISO 2002 All rights reserved Copyright International Organization for Standardization Provided by IHS under licens

9、e with ISO Licensee=Qatar Petroleum/5943408001 Not for Resale, 04/12/2007 03:04:47 MDTNo reproduction or networking permitted without license from IHS -,-,- ISO 9735-6:2002(E) ISO 2002 All rights reserved iii Contents Page Foreword.iv Introductionvi 1 Scope1 2 Conformance1 3 Normative references2 4

10、Terms and definitions .2 5 Rules for the use of the secure authentication and acknowledgement message2 Annex A (informative) AUTACK message examples.9 Annex B (informative) Security services and algorithms .22 Bibliography28 Copyright International Organization for Standardization Provided by IHS un

11、der license with ISO Licensee=Qatar Petroleum/5943408001 Not for Resale, 04/12/2007 03:04:47 MDTNo reproduction or networking permitted without license from IHS -,-,- ISO 9735-6:2002(E) iv ISO 2002 All rights reserved Foreword ISO (the International Organization for Standardization) is a worldwide f

12、ederation of national standards bodies (ISO member bodies). The work of preparing International Standards is normally carried out through ISO technical committees. Each member body interested in a subject for which a technical committee has been established has the right to be represented on that co

13、mmittee. International organizations, governmental and non-governmental, in liaison with ISO, also take part in the work. ISO collaborates closely with the International Electrotechnical Commission (IEC) on all matters of electrotechnical standardization. International Standards are drafted in accor

14、dance with the rules given in the ISO/IEC Directives, Part 3. The main task of technical committees is to prepare International Standards. Draft International Standards adopted by the technical committees are circulated to the member bodies for voting. Publication as an International Standard requir

15、es approval by at least 75 % of the member bodies casting a vote. Attention is drawn to the possibility that some of the elements of this part of ISO 9735 may be the subject of patent rights. ISO shall not be held responsible for identifying any or all such patent rights. ISO 9735-6 was prepared by

16、Technical Committee ISO/TC 154, Processes, data elements and documents in commerce, industry and administration in collaboration with UN/CEFACT through the Joint Syntax Working Group (JSWG). This second edition cancels and replaces the first edition (ISO 9735-6:1999). However ISO 9735:1988 and its A

17、mendment 1:1992 are provisionally retained for the reasons given in clause 2. Furthermore, for maintenance reasons the Syntax service directories have been removed from this and all other parts of the ISO 9735 series. They are now consolidated in a new part, ISO 9735-10. At the time of publication o

18、f ISO 9735-1:1998, ISO 9735-10 had been allocated as a part for “Security rules for interactive EDI”. This was subsequently withdrawn because of lack of user support, and as a result, all relevant references to the title “Security rules for interactive EDI” were removed in this second edition of ISO

19、 9735-6. Definitions from all parts of the ISO 9735 series have been consolidated and included in ISO 9735-1. ISO 9735 consists of the following parts, under the general title Electronic data interchange for administration, commerce and transport (EDIFACT) Application level syntax rules (Syntax vers

20、ion number: 4, Syntax release number: 1): Part 1: Syntax rules common to all parts Part 2: Syntax rules specific to batch EDI Part 3: Syntax rules specific to interactive EDI Part 4: Syntax and service report message for batch EDI (message type CONTRL) Part 5: Security rules for batch EDI (authentic

21、ity, integrity and non-repudiation of origin) Part 6: Secure authentication and acknowledgement message (message type AUTACK) Part 7: Security rules for batch EDI (confidentiality) Part 8: Associated data in EDI Copyright International Organization for Standardization Provided by IHS under license w

22、ith ISO Licensee=Qatar Petroleum/5943408001 Not for Resale, 04/12/2007 03:04:47 MDTNo reproduction or networking permitted without license from IHS -,-,- ISO 9735-6:2002(E) ISO 2002 All rights reserved v Part 9: Security key and certificate management message (message type KEYMAN) Part 10: Syntax se

23、rvice directories Further parts may be added in the future. Annexes A to C of this part of ISO 9735 are for information only. Copyright International Organization for Standardization Provided by IHS under license with ISO Licensee=Qatar Petroleum/5943408001 Not for Resale, 04/12/2007 03:04:47 MDTNo

24、reproduction or networking permitted without license from IHS -,-,- ISO 9735-6:2002(E) vi ISO 2002 All rights reserved Introduction This part of ISO 9735 includes the rules at the application level for the structuring of data in the interchange of electronic messages in an open environment, based on

25、 the requirements of either batch or interactive processing. These rules have been agreed by the United Nations Economic Commission for Europe (UN/ECE) as syntax rules for Electronic Data Interchange for Administration, Commerce and Transport (EDIFACT) and are part of the United Nations Trade Data I

26、nterchange Directory (UNTDID) which also includes both batch and interactive Message Design Guidelines. Communications specifications and protocols are outside the scope of this part of ISO 9735. This is a new part, which has been added to ISO 9735. It provides an optional capability of securing bat

27、ch EDIFACT structures, i.e. messages, packages, groups or interchanges, by means of a secure authentication and acknowledgement message. Copyright International Organization for Standardization Provided by IHS under license with ISO Licensee=Qatar Petroleum/5943408001 Not for Resale, 04/12/2007 03:0

28、4:47 MDTNo reproduction or networking permitted without license from IHS -,-,- INTERNATIONAL STANDARD ISO 9735-6:2002(E) ISO 2002 All rights reserved 1 Electronic data interchange for administration, commerce and transport (EDIFACT) Application level syntax rules (Syntax version number: 4, Syntax re

29、lease number: 1) Part 6: Secure authentication and acknowledgement message (message type AUTACK) 1 Scope This part of ISO 9735 for EDIFACT security defines the secure authentication and acknowledgement message AUTACK. 2 Conformance Whereas this part shall use a version number of “4” in the mandatory

30、 data element 0002 (Syntax version number), and shall use a release number of “01” in the conditional data element 0076 (Syntax release number), each of which appear in the segment UNB (Interchange header), interchanges continuing to use the syntax defined in the earlier published versions shall use

31、 the following Syntax version numbers, in order to differentiate them from each other and from this part: ISO 9735:1988 Syntax version number: 1 ISO 9735:1988 (amended and reprinted in 1990) Syntax version number: 2 ISO 9735:1988 and its Amendment 1:1992 Syntax version number: 3 ISO 9735:1998 Syntax

32、 version number: 4 Conformance to a standard means that all of its requirements, including all options, are supported. If all options are not supported, any claim of conformance shall include a statement which identifies those options to which conformance is claimed. Data that is interchanged is in

33、conformance if the structure and representation of the data conform to the syntax rules specified in this part of ISO 9735. Devices supporting this part of ISO 9735 are in conformance when they are capable of creating and/or interpreting the data structured and represented in conformance with this p

34、art of ISO 9735. Conformance to this part of ISO 9735 shall include conformance to parts 1, 2, 5 and 10 of ISO 9735. When identified in this part of ISO 9735, provisions defined in related standards shall form part of the conformance criteria. Copyright International Organization for Standardization

35、 Provided by IHS under license with ISO Licensee=Qatar Petroleum/5943408001 Not for Resale, 04/12/2007 03:04:47 MDTNo reproduction or networking permitted without license from IHS -,-,- ISO 9735-6:2002(E) 2 ISO 2002 All rights reserved 3 Normative references The following normative documents contain

36、 provisions which, through reference in this text, constitute provisions of this part of ISO 9735. For dated references, subsequent amendments to, or revisions of, any of these publications do not apply. However, parties to agreements based on this part of ISO 9735 are encouraged to investigate the

37、possibility of applying the most recent editions of the normative documents indicated below. For undated references, the latest edition of the normative document referred to applies. Members of ISO and IEC maintain registers of currently valid International Standards. ISO 9735-1:2002, Electronic dat

38、a interchange for administration, commerce and transport (EDIFACT) Application level syntax rules (Syntax version number: 4, Syntax release number: 1) Part 1: Syntax rules common to all parts ISO 9735-2:2002, Electronic data interchange for administration, commerce and transport (EDIFACT) Applicatio

39、n level syntax rules (Syntax version number: 4, Syntax release number: 1) Part 2: Syntax rules specific to batch EDI ISO 9735-5:2002, Electronic data interchange for administration, commerce and transport (EDIFACT) Application level syntax rules (Syntax version number: 4, Syntax release number: 1) P

40、art 5: Security rules for batch EDI (authenticity, integrity and non-repudiation of origin) ISO 9735-10:2002, Electronic data interchange for administration, commerce and transport (EDIFACT) Application level syntax rules (Syntax version number: 4, Syntax release number: 1) Part 10: Syntax service d

41、irectories 4 Terms and definitions For the purposes of this part of ISO 9735, the terms and definitions given in ISO 9735-1 apply. 5 Rules for the use of the secure authentication and acknowledgement message 5.1 Functional definition AUTACK is a message authenticating sent, or providing secure ackno

42、wledgement of received interchanges, groups, messages or packages. A secure authentication and acknowledgement message can be used to: a) give secure authentication, integrity or non-repudiation of origin to messages, packages, groups or interchanges; b) give secure acknowledgement or non-repudiatio

43、n of receipt to secured messages, packages, groups or interchanges. 5.2 Field of application The secure authentication and acknowledgement message (AUTACK) may be used for both national and international trade. It is based on universal practice related to administration, commerce and transport, and

44、is not dependent on the type of business or industry. 5.3 Principles 5.3.1 General The applied security procedures shall be agreed to by trading partners and specified in an interchange agreement. Copyright International Organization for Standardization Provided by IHS under license with ISO License

45、e=Qatar Petroleum/5943408001 Not for Resale, 04/12/2007 03:04:47 MDTNo reproduction or networking permitted without license from IHS -,-,- ISO 9735-6:2002(E) ISO 2002 All rights reserved 3 The secure authentication and acknowledgement message (AUTACK) applies security services to other EDIFACT struc

46、tures (messages, packages, groups or interchanges) and provides secure acknowledgement to secured EDIFACT structures. It can be applied to combinations of EDIFACT structures that need to be secured between two parties. The security services are provided by cryptographic mechanisms applied to the con

47、tent of the original EDIFACT structures. The results of these mechanisms form the body of the AUTACK message, supplemented by relevant data such as references of the cryptographic methods used, the reference numbers for the EDIFACT structures and the date and time of the original structures. The AUT

48、ACK message shall use the standard security header and trailer groups. The AUTACK message can apply to one or more messages, packages or groups from one or more interchanges, or to one or more interchanges. As one example, Figure 1 describes an interchange when using the AUTACK message together with one or more messages. Figure 1 Interchange showing security by using the AUTACK message at message level (sche

展开阅读全文
相关资源
猜你喜欢
相关搜索

当前位置:首页 > 其他


经营许可证编号:宁ICP备18001539号-1