Overview
ISO/IEC 19823-21:2019 specifies conformance test methods for the SIMON crypto suite as defined in ISO/IEC 29167‑21. It describes how to verify that RFID tags and interrogators (air interfaces in the ISO/IEC 18000 series) implement the mandatory functions of the SIMON-based security services correctly. The standard focuses on interoperability, protocol correctness (commands and replies), and nominal values/tolerances required for conformance testing.
Key topics and technical requirements
- Scope of testing: Conformance tests apply to RFID tags and interrogators using ISO/IEC 29167‑21 and are intended to be used alongside the ISO/IEC 18047 conformance framework.
- Conformance parameters: Parameters affecting functionality and interoperability, protocol exchanges (commands and replies), and nominal values/tolerances.
- Test methods:
- By demonstration - laboratory testing (performed by ISO/IEC 17025‑competent labs) using concrete test conditions; detailed test plans are developed by the test lab.
- By design - verification by technical analysis or vendor-provided documentation (technical memorandum); test lab issues a report on sufficiency.
- Protocol-level checks: Verification of challenge–response exchanges and message flows (TAM1, IAM1/IAM2, MAM1, etc.), generation and verification of random challenges (IChallenge, TRnd, TChallenge), and correct use of Key.KeyID in SIMON encryption/decryption (SIMON‑ENC / SIMON‑DEC).
- Parameter validation: Checks that BlockSize, KeySize, parameter sets (PS), RFU and Step fields, and Key.KeyID authorization are supported; correct error responses such as “Not Supported.”
- Test mapping: Optional features (Tag Authentication, Interrogator Authentication, Mutual Authentication, Secure Communication) are listed for explicit testing and reporting.
Applications and who uses it
- RFID manufacturers - ensure tags and interrogators conform to SIMON crypto suite requirements to achieve interoperability and predictable security behavior.
- Conformance and certification labs - implement test plans and issue conformance reports; labs should comply with ISO/IEC 17025.
- Security architects and system integrators - validate device behavior in deployed RFID systems and confirm protocol robustness.
- Compliance teams and certification bodies - include ISO/IEC 19823‑21 test results when assessing products that claim compliance with ISO/IEC 29167‑21 and related ISO/IEC 18000 parts.
Related standards
Keywords: ISO/IEC 19823‑21:2019, SIMON crypto suite, RFID conformance testing, ISO/IEC 29167‑21, ISO/IEC 18000, ISO/IEC 18047, tag authentication, interrogator authentication, RFID security.