Overview
ISO/IEC 29167-11:2023 specifies a crypto suite based on the lightweight block cipher PRESENT-80 for securing air‑interface communications in the ISO/IEC 18000 series of RFID standards. The standard defines a common set of security services for RFID air interfaces and application layers, aligned with existing air‑interface protocols. It covers both the original PRESENT variant using an 80‑bit key and the 128‑bit key variant, and provides message formats, state diagrams and conformance rules for Tags and Interrogators.
Key topics and requirements
- Crypto suite definition: Uses the PRESENT block cipher for block encryption/decryption of 64‑bit data blocks and supports both 80‑bit and 128‑bit key options.
- Authentication methods: Specifies Tag authentication (TA), Interrogator authentication (IA) and Mutual authentication (MA) message flows and formatting, with AuthMethod identifiers (e.g., “00”, “01”, “10”) for interoperability.
- Protocol elements: Includes parameter and variable definitions, initialization/reset procedures, state machine/state transition diagrams, and communication handling for air interface exchanges.
- Key management: Defines key tables and key update mechanisms so Tags and Interrogators can support one or several keyed options and explicitly declare supported methods.
- Interoperability & conformance: Details conformance rules for both Tag and Interrogator roles and protocol‑specific implementation notes (annexes include normative protocol info).
- Verification tools: Contains normative test vectors and error‑handling provisions to aid implementation testing.
- Standards governance: Notes potential patent claims and aligns with ISO/IEC editorial and patent disclosure practices.
Practical applications
- Securing low‑power, resource‑constrained RFID deployments where lightweight cryptography is required (e.g., supply chain tags, asset tracking, IoT sensors).
- Enabling mutual authentication between RFID Tags and Interrogators to prevent cloning, unauthorized reads, replay attacks and to improve privacy.
- Providing a standardized security layer for manufacturers and system integrators to achieve interoperability across different ISO/IEC 18000 air interfaces.
- Useful for developers building firmware for Tags, middleware for readers, and security assessments for the RFID ecosystem.
Who should use this standard
- RFID product designers and firmware engineers
- System integrators and solution architects for supply chain, logistics, retail and IoT
- Security engineers evaluating lightweight cryptographic options for constrained devices
- Standards bodies and test laboratories validating RFID interoperability and conformance
Related standards
Keywords: ISO/IEC 29167-11:2023, PRESENT-80, RFID security, lightweight block cipher, air interface, Tag authentication, Interrogator authentication, mutual authentication, ISO/IEC 18000.