Overview
ISO/IEC 29167-14:2015 specifies a cryptographic suite using AES in Output Feedback (OFB) mode - commonly referred to as AES-OFB - for secure air interface communications of RFID systems. Designed to complement the ISO/IEC 18000‑63 air interface (RFID Type C), this part of ISO/IEC 29167 provides a standardized, interoperable method for adding strong cryptographic protection to tag–interrogator exchanges. The standard is intended as a reference cryptographic suite that ISO committees and application developers can invoke when security for RFID air interfaces is required.
Key topics and technical requirements
- AES-OFB cipher description and operation: Defines encryption/decryption behavior in OFB mode suitable for continuous data streams between interrogator and tag.
- Authentication methods: Specifies multiple authentication types (e.g., tag authentication, interrogator authentication, mutual authentication, and initialization/authentication procedures) and the required command/response flows.
- Conformance rules: Clear requirements for claiming conformance; what interrogators and tags must implement (mandatory vs optional features).
- State and protocol behavior: State diagrams, state transition tables, initialization/reset rules, and protocol-specific operation to ensure predictable interoperable behavior.
- Key management: Master key selection, keystream generation, and key update mechanisms tailored to RFID constraints.
- Operational details and tooling: Includes normative annexes for cipher description, error codes, protocol operations and informative annexes with AES-OFB test vectors to support implementation and testing.
Practical applications
ISO/IEC 29167-14:2015 is targeted at applications that require confidentiality, integrity and authentication over the RFID air interface, particularly where large volumes of data may be exchanged or where the unique item identifier (UII) must be protected. Typical use cases include:
- Secure supply‑chain and inventory management (protecting item identifiers and sensitive read/write operations)
- Asset tracking and access control systems that require authenticated RFID interactions
- Anti‑counterfeiting and product authentication where tag identity must be verified securely
- High‑security logistics (pharma, aerospace, critical infrastructure) where over‑the‑air cryptography is required
Who should use this standard
- RFID tag designers and manufacturers implementing on‑tag crypto engines
- Interrogator/reader vendors integrating air‑interface security services
- System integrators and solution architects building secure RFID deployments
- Test and certification labs validating conformance to air interface security standards
- Standards committees and application developers referencing a standardized crypto suite for compliance
Related standards
- ISO/IEC 18000‑63 (RFID air interface Type C) - normative reference for protocol alignment
- Other parts of the ISO/IEC 29167 series (e.g., AES-128, PRESENT, ECC-DH) for alternative crypto suites and broader AIDC security guidance
Keywords: ISO/IEC 29167-14:2015, AES OFB, AES-OFB, RFID security, air interface, ISO/IEC 18000-63, cryptographic suite, authentication, key management, tag/interrogator conformance.