Overview
ISO/IEC 19823-10:2020 - Information technology - Conformance test methods for security service crypto suites - Part 10: Crypto suite AES-128 - defines standardized test methods to determine conformance of the AES‑128 crypto suite as specified in ISO/IEC 29167‑10. The document provides test procedures for all mandatory and applicable optional functions, focusing on parameters that affect system functionality and interoperability, protocol behavior (commands and replies), and nominal values and tolerances. Tests are intended for RFID Tags and Interrogators using ISO/IEC 29167‑10 with the ISO/IEC 15693 and ISO/IEC 18000 air interfaces.
Key topics and requirements
- Scope of conformance testing: Covers mandatory and optional features of the AES‑128 crypto suite; includes a test map for optional features and reporting templates.
- Test methods: Two principal approaches - by demonstration (laboratory testing) and by design (vendor technical analysis). Laboratories performing demonstrations should conform to ISO/IEC 17025 competence requirements.
- Targeted devices: Tests apply to RFID Tags and Interrogators defined in the ISO/IEC 15693 series and ISO/IEC 18000 series (including ISO/IEC 18000‑3 and 18000‑63).
- Protocol-level verification: Focus on commands and replies (e.g., Authenticate commands and related Test Authentication Messages (TAM), Interrogator Authentication Messages (IAM), and Mutual Authentication Messages (MAM) referenced in the standard).
- Test artifacts: Includes test patterns, test pattern descriptions, and additional required input parameters for reproducible conformance testing.
- Interoperability and parameters: Verifies nominal values, tolerances, memory/profile handling, and protocol conformance that affect interoperability.
Practical applications
- RFID manufacturers and firmware developers: Use the standard to validate that Tags and Interrogators correctly implement AES‑128 crypto suite behaviors required by ISO/IEC 29167‑10.
- Test laboratories and certification bodies: Apply the standardized test methods to issue conformance certificates and to ensure repeatable, objective testing; recommended to meet ISO/IEC 17025.
- System integrators and security engineers: Confirm interoperability and expected cryptographic authentication behavior across multi‑vendor deployments.
- Compliance teams: Produce evidence that devices meet protocol, command/response, and tolerance requirements for secure RFID deployments.
Related standards
Keywords: ISO/IEC 19823-10:2020, AES-128, conformance test methods, RFID, ISO/IEC 29167-10, ISO/IEC 18000, Authenticate command, TAM, IAM, MAM, test patterns, interoperability.