Overview
ISO/IEC TR 24729-4:2009 - "Information technology - Radio frequency identification for item management - Implementation guidelines - Part 4: Tag data security" - is a technical report that guides system designers on securing RFID tags and tag-to-reader communications. The report focuses on RFID security for the tag and the air interface, helping stakeholders assess threats, perform risk assessment, and choose appropriate countermeasures to protect tag data and support data access security and privacy in practical deployments.
Key Topics
- Scope and system partitioning: concentrates on items 1–2 of an RFID system (tags and tag-to-reader/tag-to-tag air interface); excludes reader-to-host and back-end enterprise security.
- Security objectives and definitions: clarifies what constitutes RFID data security - preventing unauthorized reading and modification of tag data.
- Risk assessment methodology: guidance to determine probability and impact of attacks to prioritize security measures.
- Threat taxonomy: identifies common threats such as skimming, eavesdropping/sniffing, spoofing, cloning, data tampering, malicious code, denial of service, unauthorized killing, and jamming/shielding.
- Real-world scenarios: examines example use cases (access control, contactless payment with/without PIN, loyalty cards, EPC batch tags, pharmaceutical e‑pedigree) to illustrate risk contexts.
- Countermeasures and best practices: describes technical safeguards including wafer programming (true WORM), ISO tag ID verification, license-plate approaches, memory lock, password protection, authentication, cloaking/obfuscated IDs, encryption (Annex A), and limiting read distance.
- Privacy considerations: addresses privacy in general terms, noting that data access security measures affect personal privacy even though consumer privacy is not the primary focus.
Applications
ISO/IEC TR 24729-4 is practical for:
- RFID system architects and integrators designing tag-to-reader security.
- Security analysts performing RFID risk assessments for supply chain, retail, access control, payments, healthcare, and logistics.
- Product managers and implementers selecting appropriate tag-level countermeasures (authentication, encryption, memory locks) for specific use-cases.
- Compliance teams evaluating how tag data security contributes to broader privacy and regulatory obligations.
Who should use this standard
- RFID solution designers and implementers
- Security architects and auditors
- Supply chain and asset management stakeholders
- Regulatory and privacy officers evaluating RFID deployment risks
Related standards
Keywords: ISO/IEC TR 24729-4:2009, RFID security, tag data security, radio frequency identification, tag-to-reader communication, data access security, RFID risk assessment, encryption.