ISO/IEC 13157-3:2016
Information technology — Telecommunications and information exchange between systems — NFC Security — Part 3: NFC-SEC cryptography standard using ECDH-256 and AES-GCM
Information technology — Telecommunications and information exchange between systems — NFC Security — Part 3: NFC-SEC cryptography standard using ECDH-256 and AES-GCM
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 8
- Дата публикации:
- 29 марта 2016 г.
- Издание:
- ISO/IEC IS 13157 edition 1 version 1
- ICS:
- 35.110
ISO/IEC 13157-3:2016 specifies the message contents and the cryptographic methods for PID 02. It specifies cryptographic mechanisms that use the Elliptic Curves Diffie-Hellman (ECDH) protocol with a key length of 256 bits for key agreement and the AES algorithm in GCM mode to provide data authenticated encryption.
Abstract
Overview
ISO/IEC 13157-3:2016 specifies the NFC‑SEC cryptography mechanisms for Protocol Identifier PID = 02, defining message contents and cryptographic methods for secure NFC peer-to-peer communication. The standard mandates use of Elliptic Curve Diffie‑Hellman (ECDH) with curve P‑256 (ECDH‑256) for key agreement and AES in Galois/Counter Mode (AES‑GCM) for authenticated encryption. It is part of the NFC Security series and complements ISO/IEC 13157‑1 (protocol) and ISO/IEC 13157‑2 (other cryptography variants).
Key topics and technical requirements
- Key agreement: ECDH using curve P‑256 (per FIPS 186‑4) to derive a shared secret.
- Authenticated encryption: AES‑128‑GCM for data confidentiality and integrity (t = 96-bit tag).
- Key derivation: Two KDFs for Secure Simple Exchange (SSE) and Secure Channel (SCH) based on AES‑CMAC PRF‑128 (AES‑CMAC used as PRF).
- Key confirmation: Entities exchange AES‑CMAC‑96 tags to confirm both have derived the same keys (per ISO/IEC 11770‑3).
- Nonces: Each peer sends fresh random nonces with at least 128 bits of entropy; nonces must be uncorrelated across transactions (ISO/IEC 18031 referenced).
- StartVar (IV derivation): StartVar is generated from nonces using AES‑CMAC per ISO/IEC 19772 and correlated corrigenda to ensure distinct IVs per message.
- Key usage separation: Derived keys MK, K and MK (SSE/SCH) have specific, limited purposes (master keys, authenticated encryption keys); keys must be unique per transaction.
- Protocol details: Covers primitives, message sequence integrity (SN), data conversions, and SCH/SSE invocation and data exchange for PID 02.
Practical applications
ISO/IEC 13157‑3:2016 is intended for implementing secure NFC interactions where devices do not share pre-established secrets. Typical use cases:
- Mobile payments and wallet-to-wallet transactions
- Secure pairing and data exchange between phones, wearables, and readers
- Ticketing, transit passes, and access control where short-range authenticated channels are required
- Point‑to‑point NFC file transfer with confidentiality and integrity guarantees
Who should use this standard
- NFC chipset and secure element designers
- Firmware and NFC protocol implementers
- Application developers building secure NFC services
- Security architects, evaluators, and certification bodies assessing NFC communication security
Related standards
- ISO/IEC 13157‑1 (NFC‑SEC protocol)
- ISO/IEC 13157‑2 (other NFC‑SEC cryptography)
- ISO/IEC 19772 (authenticated encryption / GCM guidance)
- ISO/IEC 9797‑1 (MAC / CMAC)
- ISO/IEC 18031 (random bit generation)
- FIPS 186‑4 (curve P‑256 parameters)
Keywords: ISO/IEC 13157‑3:2016, NFC security, NFC‑SEC, ECDH‑256, AES‑GCM, AES‑CMAC, key derivation, authenticated encryption, secure NFC channel.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 6 - Telecommunications and information exchange between systems
- SKU
- ISO/IEC 13157-3:2016
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 13157-1:2014
ДействующийInformation technology — Telecommunications and information exchange between systems — NFC Security — Part 1:…
Overview ISO/IEC 13157-1:2014 specifies the NFC-SEC protocol services and Protocol Data Units (PDUs) used to secure NFCIP-1 communications. It defines two primary services - the Shared Secret Service…
ISO/IEC 13157-2:2016
ДействующийInformation technology — Telecommunications and information exchange between systems — NFC Security — Part 2:…
Overview ISO/IEC 13157-2:2016 defines the NFC-SEC cryptography mechanisms that enable secure Near Field Communication (NFC) between devices that do not share a prior secret. The standard specifies me…
BS ISO/IEC 11770-3:2021
ДействующийInformation security. Key management. Mechanisms using asymmetric techniques.
ISO/IEC 18031:2025
ДействующийInformation technology — Security techniques — Random bit generation
Overview ISO/IEC 18031:2025 - "Information technology - Security techniques - Random bit generation" defines a conceptual model and security requirements for random bit generators (RBGs) used for cry…
BS ISO/IEC 19772:2020
ДействующийInformation security. Authenticated encryption.
ISO/IEC 9797-1:2011
ДействующийInformation technology — Security techniques — Message Authentication Codes (MACs) — Part 1: Mechanisms using…
Overview ISO/IEC 9797-1:2011 - Information technology - Security techniques - Message Authentication Codes (MACs) - Part 1: Mechanisms using a block cipher specifies six standardized MAC algorithms t…