ISO/IEC 29167-17:2015
Information technology — Automatic identification and data capture techniques — Part 17: Crypto suite cryptoGPS security services for air interface communications
Information technology — Automatic identification and data capture techniques — Part 17: Crypto suite cryptoGPS security services for air interface communications
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 39
- Дата публикации:
- 3 июня 2015 г.
- Издание:
- ISO/IEC IS 29167 edition 1 version 1
- ICS:
- 35.040
ISO/IEC 29167-17:2015 defines the cryptoGPS cryptographic suite for the ISO/IEC 18000 air interfaces standards for radio frequency identification (RFID) devices. Its purpose is to provide a common crypto suite for security for RFID devices that might be referred by ISO committees for air interface standards and application standards. ISO/IEC 29167-17:2015 defines a lightweight mechanism using asymmetric techniques and providing a unilateral authentication mechanism whose security is related to the difficulty of taking discrete logarithms on elliptic curves.
Abstract
Overview
ISO/IEC 29167-17:2015 specifies the cryptoGPS cryptographic suite for RFID air interfaces. It defines a lightweight, asymmetric security mechanism for Tag authentication on ISO/IEC 18000 air interfaces. The suite uses elliptic-curve based techniques (security tied to the difficulty of discrete logarithms on elliptic curves) and an efficient pre-computation approach using “coupons” to reduce on‑Tag computation. ISO/IEC 29167-17 provides message/response formatting, protocol states, and conformance rules for both Interrogators and Tags.
Key topics and requirements
- Scope and conformance
- Applies to ISO/IEC 18000 air interface standards for RFID.
- Defines obligations for Interrogators and Tags to claim conformance (implement message/response formats and avoid conflicting or proprietary commands).
- Asymmetric authentication
- Lightweight unilateral authentication based on elliptic-curve discrete logarithm hardness.
- Use of public/private key pairs, public domain parameters, challenges, and responses.
- Performance optimizations
- Support for offline pre-computation (“coupons”) to lower Tag computational cost while maintaining security.
- Protocol structure
- Parameter definitions, state diagram, initialization/reset, authentication flows.
- Two authentication method variants: CCR variant (Method “00” = TAM1) and NTS variant (Method “01” = TAM2).
- Operational details
- Message and response formatting, key table and key update procedures.
- Normative annexes: state transition tables, error codes, cipher description, test vectors, and protocol-specific material.
Applications and who uses it
ISO/IEC 29167-17 is intended for:
- RFID tag and reader manufacturers implementing secure air‑interface authentication.
- System integrators and solution architects in logistics, supply chain, retail, asset tracking, and IoT who require lightweight cryptographic authentication for constrained devices.
- Security engineers and standards committees selecting interoperable crypto suites for air interface and application-layer standards. Practical uses include device authentication, anti‑cloning measures, and secure identification where low Tag computation and interoperability with ISO/IEC 18000 air interfaces are critical.
Related standards
- ISO/IEC 18000 (RFID air interface parameters)
- ISO/IEC 29167-1 (Security services for RFID air interfaces)
- ISO/IEC 9798-5 (Entity authentication - zero-knowledge techniques)
- ISO/IEC 15946-1 (Elliptic curve cryptography)
- ISO/IEC 19762 (AIDC vocabulary)
- Other parts of ISO/IEC 29167 (e.g., AES-128, PRESENT-80, ECDSA‑ECDH, Grain‑128A)
For implementers, ISO/IEC 29167-17 is a practical choice when you need lightweight RFID security, elliptic-curve based authentication, and standardized interoperability across ISO/IEC 18000 air interfaces.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 31 - Automatic identification and data capture techniques
- SKU
- ISO/IEC 29167-17:2015
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC TR 20017:2011
ДействующийInformation technology — Radio frequency identification for item management — Electromagnetic interference im…
Overview ISO/IEC TR 20017:2011 is an informative Technical Report addressing the electromagnetic interference (EMI) impact of ISO/IEC 18000 RFID interrogator emitters on implantable pacemakers and im…
ISO/IEC 29167-12:2015
ДействующийInformation technology — Automatic identification and data capture techniques — Part 12: Crypto suite ECC-DH…
Overview ISO/IEC 29167-12:2015 specifies a crypto suite for ECC-DH (Elliptic Curve Diffie-Hellman) tailored to RFID air interface communications. Intended for use with the ISO/IEC 18000 family of air…
ISO/IEC 9798-5:2009
ДействующийInformation technology — Security techniques — Entity authentication — Part 5: Mechanisms using zero-knowledg…
Overview ISO/IEC 9798-5:2009 - part of the ISO/IEC 9798 series - specifies entity authentication mechanisms using zero-knowledge techniques. Published as the third edition in 2009, it defines a famil…
BS ISO/IEC 15946-1:2016
ДействующийInformation technology. Security techniques. Cryptographic techniques based on elliptic curves. General.
BS ISO/IEC 19762-5:2008
ДействующийInformation technology. Automatic identification and data capture (AIDC) techniques. Harmonized vocabulary. L…
ISO/IEC 29167-22:2018
ОтменёнInformation technology — Automatic identification and data capture techniques — Part 22: Crypto suite SPECK s…
ISO/IEC 29167-22:2018 - SPECK crypto suite for RFID air interfaces ## Overview ISO/IEC 29167-22:2018 specifies a crypto suite based on the lightweight block cipher SPECK for radio‑frequency identific…