Overview
ISO/IEC 13157-5:2016 defines NFC entity authentication and symmetric key agreement for Near Field Communication (NFC) systems. Identified as PID 04, this part of the NFC-SEC family (NEAU-S) specifies the message formats (ACT_REQ, ACT_RES, VFY_REQ, VFY_RES), cryptographic primitives and mechanisms to provide mutual authentication and key confirmation between two NFC entities that share a Pre‑Shared Authentication Key (PSAK). Successful completion produces a shared secret Z used to establish the Shared Secret Service (SSE) and Secure Channel Service (SCH).
Key topics and technical requirements
- Mutual authentication & key agreement: Uses a three‑pass authentication (per ISO/IEC 9798‑2 mechanism 4) and key establishment techniques (per ISO/IEC 11770‑2 mechanism 6).
- Symmetric cryptography (NEAU‑S): Entity authentication and key agreement are based on symmetric keys derived from the PSAK (e.g., MKA, KEIA).
- Protocol Identifier (PID): Uses one‑octet PID value 4 to identify NEAU‑S messages.
- PDUs and TLV IDs: Defines NFC‑SEC PDUs (ACT_REQ/RES, VFY_REQ/RES) and TLV encoding for entity identifiers (sender/recipient IDs).
- Cryptographic primitives: Specifies use of block ciphers (e.g., AES), Message Authentication Codes (MAC), Key Derivation Functions (KDF), IV generation methods, Additional Authenticated Data (AAD), and authenticated encryption for payload protection.
- Key confirmation and KDFs: Describes tag generation/verification for key confirmation and KDF usage for deriving MKA, KEIA and shared secrets (Z, SSE, SCH).
- Conformance: Implementations must also conform to ISO/IEC 13157‑1 and related NFC‑SEC parts.
Practical applications
ISO/IEC 13157‑5 is intended for:
- NFC device and tag manufacturers implementing NFC security features.
- Mobile wallet and contactless payment system designers requiring mutual authentication and secure channel establishment.
- Access control, transit, IoT and smartcard solution architects who need standardized symmetric authentication and key agreement.
- Security engineers and QA/certification labs validating NFC‑SEC implementations and interoperability.
Benefits include standardized mutual authentication, interoperable key agreement (shared secret Z), and integration with SSE/SCH services to protect NFC communications.
Related standards
Keywords: ISO/IEC 13157-5:2016, NFC security, NEAU-S, PSAK, symmetric cryptography, key agreement, mutual authentication, PID 04, shared secret Z, AES, KDF, NFC-SEC.