Overview
ISO/IEC 29167-10:2026 is an international standard developed by ISO and IEC that defines the use of the AES-128 crypto suite for security services in radio frequency identification (RFID) devices. This standard is a crucial part of the ISO/IEC 18000 series, focusing on enhancing security measures for automatic identification and data capture (AIDC) technologies, especially for air interface communications. ISO/IEC 29167-10:2026 specifies the application of the Advanced Encryption Standard (AES) with a 128-bit key, providing robust cryptographic solutions tailored to identification and authentication needs in RFID systems.
Key Topics
- AES-128 Security Suite: Leverages symmetric block cipher encryption using a fixed 128-bit key, offering balance between security, efficiency, and suitability for resource-constrained RFID tags.
- Authentication Services: Specifies procedures for:
- Tag authentication
- Interrogator (reader) authentication
- Mutual authentication between tag and interrogator
- Encrypted Access: Supports authenticated and encrypted reading and writing of designated memory sections on RFID tags.
- Custom Data Protection: Allows for the protection of tag memory contents through encryption or integrity checks during authentication.
- Message Exchange Framework: Defines secure message and response formatting, ensuring reliable communication over air interfaces.
- State Management: Outlines state transitions, initialization, error handling, and memory protection practices to maintain system integrity.
Applications
ISO/IEC 29167-10:2026 has broad applicability in environments that require secure RFID and AIDC systems, including:
- Supply Chain and Logistics: Protects sensitive product data and ensures the authenticity of shipped goods and items throughout transportation and warehousing.
- Access Control: Enables secure entry mechanisms in buildings, vehicles, or facilities by validating RFID credentials.
- Payment Systems: Enhances transaction confidentiality and integrity in contactless payment devices through strong encryption and authentication.
- Asset Management: Safeguards information stored on tags attached to valuable assets, reducing risks of tampering and unauthorized access.
- Healthcare and Pharmaceuticals: Protects patient data, pharmaceutical tracking, and medical device information against interception or duplication.
- Library and Archival Systems: Ensures only authorized personnel can access or modify tag data in collections management.
By implementing AES-128 crypto services at the air interface level, organizations can better meet regulatory requirements, fend off cloning and replay attacks, and maintain trust in digital identification systems.
Related Standards
- ISO/IEC 18000 Series: Core family for RFID air interface protocols covering various frequency ranges and use cases.
- ISO/IEC 29167-1: General security services for RFID air interfaces.
- ISO/IEC 19762: Vocabulary for automatic identification and data capture techniques.
- ISO/IEC 18033-3: Standardization of block ciphers, including AES.
- FIPS PUB 197: National standard for AES, referenced for implementation best practices.
Practical Value
Adopting ISO/IEC 29167-10:2026 empowers organizations to:
- Implement industry-proven AES-128 cryptography for RFID applications.
- Achieve strong data confidentiality, integrity, and authentication at the physical interface layer.
- Fulfill global best practices and regulatory expectations for secure AIDC communications.
Effective use of this standard protects against tampering, eavesdropping, and counterfeiting, supporting robust security for modern RFID deployments.