Overview
ISO/IEC 29167-10:2017 defines a standardized AES-128 crypto suite for air-interface communications in RFID systems. Intended for use with the ISO/IEC 18000 family of air interface standards, this part of ISO/IEC 29167 provides a common set of security services and message formats so Tags and Interrogators can implement interoperable authentication and encryption on radio links.
Key topics and technical requirements
- Crypto algorithm: AES with a fixed 128-bit key (AES-128) used in ECB and CBC modes, and MAC generation (AES-CMAC-96) as specified in the document.
- Authentication methods: Defines Tag Authentication (TAM), Interrogator Authentication (IAM) and Mutual Authentication (MAM), with message/response sequences and state diagrams.
- Message formats and procedures: Specifies message/response blocks, initialization/reset procedures, and how custom data can be included in authentication exchanges.
- Encryption direction: The crypto suite supports encryption on the Tag side for encrypting messages sent from Tag→Interrogator and decrypting messages received from Interrogator→Tag.
- Conformance: Requirements and obligations for both Interrogator and Tag implementations, including how supported options must be declared.
- Key management: Key tables and KeyUpdate mechanisms are defined to support operational key lifecycle.
- Normative and informative annexes: Includes cipher description, state transition tables, error handling, protocol-specific information and test vectors to aid implementation and testing.
Practical applications
- Securing RFID communications in supply chain, inventory, asset tracking, and access control systems where ISO/IEC 18000 air interfaces are used.
- Enabling interoperable RFID security implementations across manufacturers by providing a common AES-128 crypto suite and standardized authentication methods.
- Use cases that require authenticated reads (Tag Authentication) or authenticated writes (Interrogator Authentication), and scenarios that demand mutual authentication for higher trust.
- Developers of RFID tags, interrogators/readers, middleware vendors, system integrators and standards committees referencing air-interface security.
Who should use this standard
- RFID hardware designers implementing interoperable security on ISO/IEC 18000 air interfaces.
- Firmware and protocol engineers responsible for Tag/Interrogator authentication and encryption.
- Test labs and integrators validating conformity to ISO security services and interoperability.
- Standards bodies and application profile authors that need a harmonized AES-128 crypto profile for RFID air interfaces.
Related standards
Keywords: ISO/IEC 29167-10:2017, AES-128, RFID security, air interface, crypto suite, Tag Authentication, Interrogator Authentication, mutual authentication, AES-CMAC-96, ISO/IEC 18000.