Overview
ISO/IEC 13157-4:2016 defines NFC-SEC entity authentication and key agreement using asymmetric cryptography. Part 4 of the NFC Security series (PID 03) specifies message contents, cryptographic mechanisms and transport protocol requirements for mutual authentication and key agreement between NFC entities (Sender, Recipient) and optional Trusted Third Parties (TTP). It extends services in ISO/IEC 13157-3 by adding entity authentication for Shared Secret Service (SSE) and Secure Channel Service (SCH).
Keywords: NFC security, NFC-SEC, ISO/IEC 13157-4, entity authentication, asymmetric cryptography, mutual authentication.
Key topics and technical requirements
- NEAU-A mechanism: Defines NFC Entity Authentication using asymmetric cryptography for mutual authentication and key agreement.
- Message formats and PDUs: Fields, protocol identifiers (PID 03), and NFC-SEC PDUs are specified for interoperability.
- Entity identifiers and certificates: Use of certificates (CertA, CertB, CertTTP) and X.509-style validation for authenticating public keys.
- Asymmetric algorithms and signatures: Support for elliptic-curve based mechanisms including EC curve selection and ECDSA for digital signatures (ECDSA test vectors provided in Annex B).
- Key agreement and confirmation: Procedures for deriving shared keys, key confirmation and Key Derivation Function (KDF) usage to produce session keys for SSE and SCH.
- TTP interaction: Transport and policy negotiation between Sender and TTP, including certificate validation responsibilities of TTP implementations.
- Transport considerations: Protocol transport requirements and an informative Annex A covering UDP port 5111 and the TAEP packet format for TTP exchanges.
- Conformance: Entities must also conform to ISO/IEC 13157-1 and related cryptography parts (Part 2/3) and referenced standards such as ISO/IEC 9798-1, ISO/IEC 11770-3 and X.509.
Practical applications and who uses it
- NFC device manufacturers: Implementers of secure NFC stacks (readers, tags, mobile devices) to provide interoperable mutual authentication and secure channels.
- Payment and transit systems: Operators and vendors who need authenticated key agreement for contactless payments, ticketing and transit passes.
- Access control and identity: Providers of secure NFC access cards, smartcards and mobile access credentials requiring certificate-based authentication.
- Security architects and software developers: Designers building NFC-secured applications that rely on asymmetric key mechanisms, certificate validation and standard KDF/signature processes.
- TTP implementers and service providers: Entities operating certificate validation or policy negotiation services for NFC ecosystems.
Related standards
ISO/IEC 13157-4:2016 is essential when building secure, standards-compliant NFC authentication and key-agreement flows that use asymmetric cryptography and certificate-based trust.