Overview
ISO/IEC 19823-13:2018 specifies conformance test methods for the Grain-128A cryptographic suite as defined in ISO/IEC 29167-13. It defines how to verify that RFID tags and interrogators (air interfaces in the ISO/IEC 18000 series) implement the Grain-128A security services correctly. The standard focuses on protocol behavior, command/response handling, and nominal parameter values and tolerances required for interoperability.
Key topics and requirements
- Scope and applicability
- Conformance parameters
- Parameters affecting functionality and interoperability, protocol commands and replies, and nominal values/tolerances.
- Test methods
- Two verification approaches: By demonstration (laboratory testing) and By design (technical analysis/documentation). Laboratory testing should be performed by ISO/IEC 17025–accredited facilities.
- Protocol and state handling
- Requirements for crypto engine states such as CS-Reset and CS-Init, error reporting (ERROR flag), and an external reset behavior (INIT, TA, IA, ERROR flags).
- Authentication features
- Support and testing for Tag Authentication (TA), Interrogator Authentication (IA), Mutual Authentication, Options and Steps fields, KeyID handling, and CSFeatures reporting.
- Optional functions and test mapping
- Table-driven mapping of optional features (TA, IA, Secure Communication, Key update) to specific test requirements and test patterns (e.g., Test Pattern 1, 2, 3, 8, 9, 10, 14, 15, 16).
- Mandatory vs optional testing
- Items marked “M” must be tested for all devices; “O” only when the device implements that feature.
Applications and who uses it
- RFID manufacturers and firmware developers: to validate that Grain-128A implementations conform to ISO/IEC 29167-13.
- Conformance and interoperability test laboratories: to perform standardized tests and issue compliance certificates.
- System integrators and security evaluators: to ensure secure air-interface behavior (authentication, SecureComm, key updates) in ISO/IEC 18000-based deployments.
- Regulatory and procurement teams: to specify and verify crypto suite conformance in product acceptance.
Related standards
Keywords: ISO/IEC 19823-13:2018, Grain-128A, conformance test methods, RFID security, ISO/IEC 29167-13, ISO/IEC 18000, authentication, SecureComm, key update, test laboratory.