ISO/IEC 29167-10:2026
Information technology — Automatic identification and data capture techniques — Part 10: Crypto suite AES-128 security services for air interface communications
Information technology — Automatic identification and data capture techniques — Part 10: Crypto suite AES-128 security services for air interface communications
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 54
- Дата публикации:
- 6 марта 2026 г.
- Издание:
- ISO/IEC IS 29167 edition 3 version 1
- ICS:
- 35.040.50
This document specifies the crypto suite for AES-128 for the ISO/IEC 18000 air interface standards for radio frequency identification (RFID) devices. This document specifies the security services of an AES-128 crypto suite. AES has a fixed block size of 128 bits and a key size of 128 bits, 192 bits or 256 bits. This document uses AES with a fixed key size of 128 bits and is referred to as AES-128. This document specifies procedures for the authentication of a Tag and or an Interrogator using AES-128 and provides the following features: Tag authentication; Tag authentication allowing authenticated and encrypted reading of part of the Tag’s memory; Interrogator authentication; Interrogator authentication allowing authenticated and encrypted writing of part of the Tag’s memory; Mutual authentication. In this document, a Tag and an Interrogator can support one, a subset, or all of the specified options, clearly stating what is supported.
Abstract
Overview
ISO/IEC 29167-10:2026 is an international standard developed by ISO and IEC that defines the use of the AES-128 crypto suite for security services in radio frequency identification (RFID) devices. This standard is a crucial part of the ISO/IEC 18000 series, focusing on enhancing security measures for automatic identification and data capture (AIDC) technologies, especially for air interface communications. ISO/IEC 29167-10:2026 specifies the application of the Advanced Encryption Standard (AES) with a 128-bit key, providing robust cryptographic solutions tailored to identification and authentication needs in RFID systems.
Key Topics
- AES-128 Security Suite: Leverages symmetric block cipher encryption using a fixed 128-bit key, offering balance between security, efficiency, and suitability for resource-constrained RFID tags.
- Authentication Services: Specifies procedures for:
- Tag authentication
- Interrogator (reader) authentication
- Mutual authentication between tag and interrogator
- Encrypted Access: Supports authenticated and encrypted reading and writing of designated memory sections on RFID tags.
- Custom Data Protection: Allows for the protection of tag memory contents through encryption or integrity checks during authentication.
- Message Exchange Framework: Defines secure message and response formatting, ensuring reliable communication over air interfaces.
- State Management: Outlines state transitions, initialization, error handling, and memory protection practices to maintain system integrity.
Applications
ISO/IEC 29167-10:2026 has broad applicability in environments that require secure RFID and AIDC systems, including:
- Supply Chain and Logistics: Protects sensitive product data and ensures the authenticity of shipped goods and items throughout transportation and warehousing.
- Access Control: Enables secure entry mechanisms in buildings, vehicles, or facilities by validating RFID credentials.
- Payment Systems: Enhances transaction confidentiality and integrity in contactless payment devices through strong encryption and authentication.
- Asset Management: Safeguards information stored on tags attached to valuable assets, reducing risks of tampering and unauthorized access.
- Healthcare and Pharmaceuticals: Protects patient data, pharmaceutical tracking, and medical device information against interception or duplication.
- Library and Archival Systems: Ensures only authorized personnel can access or modify tag data in collections management.
By implementing AES-128 crypto services at the air interface level, organizations can better meet regulatory requirements, fend off cloning and replay attacks, and maintain trust in digital identification systems.
Related Standards
- ISO/IEC 18000 Series: Core family for RFID air interface protocols covering various frequency ranges and use cases.
- ISO/IEC 18000-3: Air interface parameters at 13.56 MHz for item management.
- ISO/IEC 18000-63: Air interface parameters for UHF RFID (860-930 MHz).
- ISO/IEC 29167-1: General security services for RFID air interfaces.
- ISO/IEC 19762: Vocabulary for automatic identification and data capture techniques.
- ISO/IEC 18033-3: Standardization of block ciphers, including AES.
- FIPS PUB 197: National standard for AES, referenced for implementation best practices.
Practical Value
Adopting ISO/IEC 29167-10:2026 empowers organizations to:
- Implement industry-proven AES-128 cryptography for RFID applications.
- Achieve strong data confidentiality, integrity, and authentication at the physical interface layer.
- Fulfill global best practices and regulatory expectations for secure AIDC communications.
Effective use of this standard protects against tampering, eavesdropping, and counterfeiting, supporting robust security for modern RFID deployments.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 31 - Automatic identification and data capture techniques
- SKU
- ISO/IEC 29167-10:2026
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC TR 20017:2011
ДействующийInformation technology — Radio frequency identification for item management — Electromagnetic interference im…
Overview ISO/IEC TR 20017:2011 is an informative Technical Report addressing the electromagnetic interference (EMI) impact of ISO/IEC 18000 RFID interrogator emitters on implantable pacemakers and im…
BS ISO/IEC 18000-3:2010
ДействующийInformation technology. Radio frequency identification for item management. Parameters for air interface comm…
ISO/IEC 18000-63:2015
ОтменёнInformation technology — Radio frequency identification for item management — Part 63: Parameters for air int…
ISO/IEC 29167-12:2015
ДействующийInformation technology — Automatic identification and data capture techniques — Part 12: Crypto suite ECC-DH…
Overview ISO/IEC 29167-12:2015 specifies a crypto suite for ECC-DH (Elliptic Curve Diffie-Hellman) tailored to RFID air interface communications. Intended for use with the ISO/IEC 18000 family of air…
BS ISO/IEC 19762-5:2008
ДействующийInformation technology. Automatic identification and data capture (AIDC) techniques. Harmonized vocabulary. L…
ISO/IEC 18033-3:2010
ДействующийInformation technology — Security techniques — Encryption algorithms — Part 3: Block ciphers
Overview ISO/IEC 18033-3:2010 - "Information technology - Security techniques - Encryption algorithms - Part 3: Block ciphers" is the international standard that specifies a set of block cipher algor…