ISO/IEC 13157-5:2016
Information technology — Telecommunications and information exchange between systems — NFC Security — Part 5: NFC-SEC entity authentication and key agreement using symmetric cryptography
Information technology — Telecommunications and information exchange between systems — NFC Security — Part 5: NFC-SEC entity authentication and key agreement using symmetric cryptography
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 11
- Дата публикации:
- 10 июня 2016 г.
- Издание:
- ISO/IEC IS 13157 edition 1 version 1
- ICS:
- 35.110
ISO/IEC 13157-5:2016 specifies the message contents and the cryptographic mechanisms for PID 04. ISO/IEC 13157-5:2016 specifies key agreement and confirmation mechanisms providing mutual authentication, using symmetric cryptography. ISO/IEC 13157-5:2016 adds entity authentication to the services provided by ISO/IEC 13157-3 (ECMA‑409) NFC-SEC-02.
Abstract
Overview
ISO/IEC 13157-5:2016 defines NFC entity authentication and symmetric key agreement for Near Field Communication (NFC) systems. Identified as PID 04, this part of the NFC-SEC family (NEAU-S) specifies the message formats (ACT_REQ, ACT_RES, VFY_REQ, VFY_RES), cryptographic primitives and mechanisms to provide mutual authentication and key confirmation between two NFC entities that share a Pre‑Shared Authentication Key (PSAK). Successful completion produces a shared secret Z used to establish the Shared Secret Service (SSE) and Secure Channel Service (SCH).
Key topics and technical requirements
- Mutual authentication & key agreement: Uses a three‑pass authentication (per ISO/IEC 9798‑2 mechanism 4) and key establishment techniques (per ISO/IEC 11770‑2 mechanism 6).
- Symmetric cryptography (NEAU‑S): Entity authentication and key agreement are based on symmetric keys derived from the PSAK (e.g., MKA, KEIA).
- Protocol Identifier (PID): Uses one‑octet PID value 4 to identify NEAU‑S messages.
- PDUs and TLV IDs: Defines NFC‑SEC PDUs (ACT_REQ/RES, VFY_REQ/RES) and TLV encoding for entity identifiers (sender/recipient IDs).
- Cryptographic primitives: Specifies use of block ciphers (e.g., AES), Message Authentication Codes (MAC), Key Derivation Functions (KDF), IV generation methods, Additional Authenticated Data (AAD), and authenticated encryption for payload protection.
- Key confirmation and KDFs: Describes tag generation/verification for key confirmation and KDF usage for deriving MKA, KEIA and shared secrets (Z, SSE, SCH).
- Conformance: Implementations must also conform to ISO/IEC 13157‑1 and related NFC‑SEC parts.
Practical applications
ISO/IEC 13157‑5 is intended for:
- NFC device and tag manufacturers implementing NFC security features.
- Mobile wallet and contactless payment system designers requiring mutual authentication and secure channel establishment.
- Access control, transit, IoT and smartcard solution architects who need standardized symmetric authentication and key agreement.
- Security engineers and QA/certification labs validating NFC‑SEC implementations and interoperability.
Benefits include standardized mutual authentication, interoperable key agreement (shared secret Z), and integration with SSE/SCH services to protect NFC communications.
Related standards
- ISO/IEC 13157‑1: NFC‑SEC services and protocol (ECMA‑385)
- ISO/IEC 13157‑2: NFC‑SEC cryptography using ECDH and AES (ECMA‑386)
- ISO/IEC 13157‑3: NFC‑SEC using ECDH‑256 and AES‑GCM (ECMA‑409)
- ISO/IEC 9798, 11770 series, and ISO/IEC 18092 for related NFC and cryptographic guidance
Keywords: ISO/IEC 13157-5:2016, NFC security, NEAU-S, PSAK, symmetric cryptography, key agreement, mutual authentication, PID 04, shared secret Z, AES, KDF, NFC-SEC.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 6 - Telecommunications and information exchange between systems
- SKU
- ISO/IEC 13157-5:2016
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 9798-2:2008
ОтменёнInformation technology — Security techniques — Entity authentication — Part 2: Mechanisms using symmetric enc…
BS ISO/IEC 11770-2:2018
ДействующийIT Security techniques. Key management. Mechanisms using symmetric techniques.
ISO/IEC 13157-1:2014
ДействующийInformation technology — Telecommunications and information exchange between systems — NFC Security — Part 1:…
Overview ISO/IEC 13157-1:2014 specifies the NFC-SEC protocol services and Protocol Data Units (PDUs) used to secure NFCIP-1 communications. It defines two primary services - the Shared Secret Service…
ISO/IEC 13157-2:2016
ДействующийInformation technology — Telecommunications and information exchange between systems — NFC Security — Part 2:…
Overview ISO/IEC 13157-2:2016 defines the NFC-SEC cryptography mechanisms that enable secure Near Field Communication (NFC) between devices that do not share a prior secret. The standard specifies me…
ISO/IEC 13157-3:2016
ДействующийInformation technology — Telecommunications and information exchange between systems — NFC Security — Part 3:…
Overview ISO/IEC 13157-3:2016 specifies the NFC‑SEC cryptography mechanisms for Protocol Identifier PID = 02, defining message contents and cryptographic methods for secure NFC peer-to-peer communica…