Overview
ISO/IEC 29167-21:2026 - "Information technology - Automatic identification and data capture techniques - Part 21: Crypto suite SIMON security services for air interface communications" - is an international standard developed by the ISO and IEC. This standard specifies the use of a crypto suite based on the SIMON block cipher for secure communications in radio frequency identification (RFID) devices using ISO/IEC 18000 air interfaces. The SIMON cipher supports various block and key lengths, offering flexibility and robust protection for automatic identification and data capture (AIDC) applications.
Key Topics
- SIMON Block Cipher:
A symmetric, lightweight Feistel cipher optimized for environments with limited computing resources, such as RFID tags and readers.
- Configurable Security:
Five block/key lengths are supported: 64/96, 96/96, 64/128, 128/128, and 128/256 bits, allowing manufacturers to tailor security per device capabilities or use cases.
- RFID Air Interface Integration:
Specifically designed for compatibility with ISO/IEC 18000 RFID air interface standards, maximizing interoperability across deployments.
- Authentication Methods:
- Tag Authentication: Verifies the legitimacy of RFID tags.
- Interrogator Authentication: Confirms the authenticity of RFID scanners (interrogators).
- Mutual Authentication: Ensures both tag and interrogator credentials align, providing comprehensive two-way security.
- Protocol Compliance:
Addresses mandatory and optional commands, clear conformance requirements, and error-handling procedures, ensuring seamless and standardized implementation.
- Key Management:
While the SIMON crypto suite allows multiple cryptographic keys, the specifics of key management are left to implementers, supporting up to 256 keyed identities per device.
Applications
The SIMON crypto suite for RFID is ideally suited for:
- Supply Chain Security:
Ensures only authorized tags and readers can communicate, reducing the risk of counterfeiting and unauthorized access to item-level data.
- Retail and Inventory Management:
Enhances privacy and product authenticity checks, thus supporting anti-theft, stock control, and point-of-sale validation.
- Access Control and Authentication:
Provides robust mutual authentication for secure entry/systems control using RFID credentials, improving resistance to cloning attacks.
- Asset Tracking in Logistics:
Protects sensitive asset location and status information during transportation, even in resource-constrained environments.
- Healthcare and Pharmaceutical Tracking:
Supports secure patient, equipment, and medication identification, adding cryptographic assurance to compliance processes.
- Critical Infrastructure:
Safeguards authentication and control of components in utilities, transportation, and industrial automation sectors.
Adopting ISO/IEC 29167-21:2026 delivers enhanced security for RFID applications, aligns with global data protection standards, and reduces interoperability risks across multi-vendor environments.
Related Standards
Organizations implementing this standard should also consider:
- ISO/IEC 29167 Series:
Covers a range of cryptographic suites for RFID, including AES and other lightweight options.
- ISO/IEC 18000 Series:
Specifies air interface protocols for RFID devices, with particular emphasis on Part 63 for 860 MHz–960 MHz systems.
- ISO/IEC 19762:
AIDC vocabulary standard, offering definitions for terms and abbreviations used in this and related standards.
- ISO/IEC 29167-10:
AES-based security services for similar AIDC applications, which can be complementary or serve as alternatives to SIMON in certain deployments.
Practical Value
Implementing ISO/IEC 29167-21:2026 enables organizations to deploy advanced cryptographic security in RFID and AIDC environments, striking the right balance between data protection and device performance. The standardized approach ensures scalable authentication across industries, supports secure global commerce, and strengthens defenses against evolving cyber threats in automatic identification and data capture systems.