--- a/Ieee1609Dot2.asn +++ b/Ieee1609Dot2.asn @@ -10,7 +10,7 @@ Ieee1609Dot2 {iso(1) identified-organization(3) ieee(111) standards-association-numbered-series-standards(2) wave-stds(1609) - dot2(2) base(1) schema(1) major-version-2(2) minor-version-7(7)} + dot2(2) base(1) schema(1) major-version-2(2) minor-version-8(8)} DEFINITIONS AUTOMATIC TAGS ::= BEGIN @@ -24,6 +24,7 @@ EXT-TYPE, Extension, ExtId, + FnDsa512Key, GeographicRegion, GroupLinkageValue, HashAlgorithm, @@ -1048,6 +1049,13 @@ * @param certRequestExtensions: indicates additional permissions to request * certificates containing endEntityExtensions. * + * @param altVerificationKey: carries the alternative FN-DSA-512 public key + * in a hybrid authority certificate. It is absent from end-entity + * authorization tickets. + * + * @param altSignatureValue: carries the FN-DSA-512 signature generated by + * the issuer over this certificate. + * * @note In IEEE Std 1609.2-2022 these were not marked optional; they are in * this version of the standard; this is technically not backwards compatible * but in practice there are no scenarios in which a legacy system will break @@ -1160,7 +1168,9 @@ flags BIT STRING {usesCubk (0)} (SIZE (8)) OPTIONAL, appExtensions SequenceOfAppExtensions OPTIONAL, certIssueExtensions SequenceOfCertIssueExtensions OPTIONAL, - certRequestExtension SequenceOfCertRequestExtensions OPTIONAL + certRequestExtension SequenceOfCertRequestExtensions OPTIONAL, + altVerificationKey PublicVerificationKey OPTIONAL, + altSignatureValue Signature OPTIONAL } (WITH COMPONENTS { ..., appPermissions PRESENT} | WITH COMPONENTS { ..., certIssuePermissions PRESENT} | --- a/Ieee1609Dot2BaseTypes.asn +++ b/Ieee1609Dot2BaseTypes.asn @@ -10,7 +10,7 @@ Ieee1609Dot2BaseTypes {iso(1) identified-organization(3) ieee(111) standards-association-numbered-series-standards(2) wave-stds(1609) dot2(2) - base(1) base-types(2) major-version-2(2) minor-version-5(5)} + base(1) base-types(2) major-version-2(2) minor-version-6(6)} DEFINITIONS AUTOMATIC TAGS ::= BEGIN @@ -724,7 +724,8 @@ ..., ecdsaBrainpoolP384r1Signature EcdsaP384Signature, ecdsaNistP384Signature EcdsaP384Signature, - sm2Signature EcsigP256Signature + sm2Signature EcsigP256Signature, + fnDsa512Signature FnDsa512Signature } /** @@ -821,6 +822,12 @@ } /** + * @brief This type contains an FN-DSA-512 signature as a fixed-size octet + * string. + */ +FnDsa512Signature ::= OCTET STRING (SIZE (666)) + +/** * @brief This structure specifies a point on an elliptic curve in Weierstrass * form defined over a 256-bit prime number. The curves supported in this * standard are NIST p256 as defined in FIPS 186-5, Brainpool p256r1 as @@ -888,6 +895,12 @@ } /** + * @brief This type contains an FN-DSA-512 public verification key as a + * fixed-size octet string. + */ +FnDsa512Key ::= OCTET STRING (SIZE (897)) + +/** * @brief This enumerated value indicates supported symmetric algorithms. The * algorithm identifier identifies both the algorithm itself and a specific * mode of operation. The symmetric algorithms supported in this version of @@ -1045,7 +1058,8 @@ ... , ecdsaBrainpoolP384r1 EccP384CurvePoint, ecdsaNistP384 EccP384CurvePoint, - ecsigSm2 EccP256CurvePoint + ecsigSm2 EccP256CurvePoint, + fnDsa512 FnDsa512Key } /**