ISO/IEC 13157-4:2016
Information technology — Telecommunications and information exchange between systems — NFC Security — Part 4: NFC-SEC entity authentication and key agreement using asymmetric cryptography
Information technology — Telecommunications and information exchange between systems — NFC Security — Part 4: NFC-SEC entity authentication and key agreement using asymmetric cryptography
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 25
- Дата публикации:
- 10 июня 2016 г.
- Издание:
- ISO/IEC IS 13157 edition 1 version 1
- ICS:
- 35.110
ISO/IEC 13157-4:2016 specifies the message contents and the cryptographic mechanisms for PID 03. ISO/IEC 13157-4:2016 specifies key agreement and confirmation mechanisms providing mutual authentication, using asymmetric cryptography, and the transport protocol requirements for the exchange between Sender and TTP. NOTE ISO/IEC 13157-4:2016 adds entity authentication to the services provided by ISO/IEC 13157-3 (ECMA-409) NFC-SEC-02.
Abstract
Overview
ISO/IEC 13157-4:2016 defines NFC-SEC entity authentication and key agreement using asymmetric cryptography. Part 4 of the NFC Security series (PID 03) specifies message contents, cryptographic mechanisms and transport protocol requirements for mutual authentication and key agreement between NFC entities (Sender, Recipient) and optional Trusted Third Parties (TTP). It extends services in ISO/IEC 13157-3 by adding entity authentication for Shared Secret Service (SSE) and Secure Channel Service (SCH).
Keywords: NFC security, NFC-SEC, ISO/IEC 13157-4, entity authentication, asymmetric cryptography, mutual authentication.
Key topics and technical requirements
- NEAU-A mechanism: Defines NFC Entity Authentication using asymmetric cryptography for mutual authentication and key agreement.
- Message formats and PDUs: Fields, protocol identifiers (PID 03), and NFC-SEC PDUs are specified for interoperability.
- Entity identifiers and certificates: Use of certificates (CertA, CertB, CertTTP) and X.509-style validation for authenticating public keys.
- Asymmetric algorithms and signatures: Support for elliptic-curve based mechanisms including EC curve selection and ECDSA for digital signatures (ECDSA test vectors provided in Annex B).
- Key agreement and confirmation: Procedures for deriving shared keys, key confirmation and Key Derivation Function (KDF) usage to produce session keys for SSE and SCH.
- TTP interaction: Transport and policy negotiation between Sender and TTP, including certificate validation responsibilities of TTP implementations.
- Transport considerations: Protocol transport requirements and an informative Annex A covering UDP port 5111 and the TAEP packet format for TTP exchanges.
- Conformance: Entities must also conform to ISO/IEC 13157-1 and related cryptography parts (Part 2/3) and referenced standards such as ISO/IEC 9798-1, ISO/IEC 11770-3 and X.509.
Practical applications and who uses it
- NFC device manufacturers: Implementers of secure NFC stacks (readers, tags, mobile devices) to provide interoperable mutual authentication and secure channels.
- Payment and transit systems: Operators and vendors who need authenticated key agreement for contactless payments, ticketing and transit passes.
- Access control and identity: Providers of secure NFC access cards, smartcards and mobile access credentials requiring certificate-based authentication.
- Security architects and software developers: Designers building NFC-secured applications that rely on asymmetric key mechanisms, certificate validation and standard KDF/signature processes.
- TTP implementers and service providers: Entities operating certificate validation or policy negotiation services for NFC ecosystems.
Related standards
- ISO/IEC 13157-1 (NFC-SEC services & protocol)
- ISO/IEC 13157-2 and -3 (NFC-SEC cryptography standards)
- ISO/IEC 9798-1 / 9798-3 (entity authentication)
- ISO/IEC 11770-3 (key management using asymmetric techniques)
- ITU-T X.509 (public-key certificates)
ISO/IEC 13157-4:2016 is essential when building secure, standards-compliant NFC authentication and key-agreement flows that use asymmetric cryptography and certificate-based trust.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 6 - Telecommunications and information exchange between systems
- SKU
- ISO/IEC 13157-4:2016
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 13157-3:2016
ДействующийInformation technology — Telecommunications and information exchange between systems — NFC Security — Part 3:…
Overview ISO/IEC 13157-3:2016 specifies the NFC‑SEC cryptography mechanisms for Protocol Identifier PID = 02, defining message contents and cryptographic methods for secure NFC peer-to-peer communica…
ISO/IEC 13157-1:2014
ДействующийInformation technology — Telecommunications and information exchange between systems — NFC Security — Part 1:…
Overview ISO/IEC 13157-1:2014 specifies the NFC-SEC protocol services and Protocol Data Units (PDUs) used to secure NFCIP-1 communications. It defines two primary services - the Shared Secret Service…
ISO/IEC 9798-1:2010
ДействующийInformation technology — Security techniques — Entity authentication — Part 1: General
Overview - ISO/IEC 9798-1:2010 (Entity authentication - General) ISO/IEC 9798-1:2010 defines the authentication model, terminology, and general requirements for entity authentication mechanisms that…
BS ISO/IEC 11770-3:2021
ДействующийInformation security. Key management. Mechanisms using asymmetric techniques.
ISO/IEC 13157-2:2016
ДействующийInformation technology — Telecommunications and information exchange between systems — NFC Security — Part 2:…
Overview ISO/IEC 13157-2:2016 defines the NFC-SEC cryptography mechanisms that enable secure Near Field Communication (NFC) between devices that do not share a prior secret. The standard specifies me…