Information technology — Automatic identification and data capture techniques — Part 1: Security services for RFID air interfaces

ISO/IEC 29167-1:2014 defines the architecture for security services for the ISO/IEC 18000 air interfaces standards for radio frequency identification (RFID) devices. Its purpose is to provide a common technical specification for optional security services for RFID devices that may be used by ISO committees developing RFID application standards. ISO/IEC 29167-1:2014 defines various security features called security mechanisms that can be implemented by a tag depending on the application. A tag may support one, a subset, or all of the specified security mechanisms. For an interrogator it is possible to get information about the security mechanisms that are actually implemented and supported by a tag. Moreover, it has been considered that adding new security mechanisms remains possible. Besides signalling the presence of certain security services, further details of the mechanisms such as utilized encryption algorithm and key length also need to be specified and accessible. ISO/IEC 29167-1:2014 defines the requirements for crypto suites defined in further parts of ISO/IEC 29167 and furthermore defines how crypto suites identifiers are assigned to the various parts of ISO/IEC 29167.

Technologies de l'information — Techniques automatiques d'identification et de capture de données — Partie 1: Services de sécurité pour les interfaces radio RFID

General Information

Status
Published
Publication Date
05-Aug-2014
Current Stage
9093 - International Standard confirmed
Start Date
11-Nov-2025
Completion Date
14-Feb-2026

Relations

Effective Date
10-Dec-2011

Overview

ISO/IEC 29167-1:2014 is a fundamental international standard developed by ISO and IEC, defining the architecture for security services applied to RFID air interfaces as specified in the ISO/IEC 18000 series. Specifically targeting automatic identification and data capture (AIDC), this standard establishes a technical specification for optional security services in RFID systems, addressing key issues such as privacy, integrity, authentication, and confidentiality of data on RFID tags.

The overarching goal of ISO/IEC 29167-1:2014 is to improve the security of RFID devices, enabling organizations to safeguard sensitive information, prevent unauthorized access, and protect the identity of items and individuals interacting with RFID technology.

Key Topics

  • Security Mechanisms

    • Untraceability: Provides options to hide or limit tag identification, reducing the risk of unauthorized tracking.
    • Authentication: Frameworks for verifying the authenticity of tags, interrogators, and exchanged data.
    • Secure Access and Encryption: Mechanisms for controlling and securing access to tag data and functions.
    • Cryptographic Suites: Modular cryptographic functions, with the flexibility for tags to support one or more suites.
  • Privacy and Data Protection

    • Built-in privacy-by-design and security-by-design features to minimize unauthorized data collection and access.
    • Support for organizing tag data into files with tailored access rights.
  • Discovery and File Management

    • Methods for interrogators to discover supported tag features, security mechanisms, and file management schemas.
    • Mechanisms for authorized identification of untraceable tags and dynamic management of tag memory and permissions.
  • Crypto Suite Indicator (CSI) Assignment

    • Structured allocation of identifiers to different cryptographic suites for interoperability and scalability, supporting extension as new suites are developed.

Applications

ISO/IEC 29167-1:2014 provides significant practical value in a range of RFID applications where enhanced security is required:

  • Supply Chain Management:
    Protecting items against counterfeit and ensuring data integrity during shipping and logistics.

  • Asset and Inventory Tracking:
    Safeguarding asset identity and ensuring only authorized users can access sensitive inventory data.

  • Access Control:
    Enabling secure entry systems, preventing cloning or unauthorized access via RFID-enabled credentials.

  • Healthcare and Pharmaceuticals:
    Protecting patient privacy and securing the cross-movement of medical equipment and drugs.

  • Retail and Customer Privacy:
    Minimizing in-store tracking of individuals and protecting the confidentiality of purchase data.

By incorporating ISO/IEC 29167-1:2014, organizations can align their RFID deployments with international best practices for security, reduce compliance risks, and strengthen trust among stakeholders.

Related Standards

This standard is part of a comprehensive framework for RFID security within the ISO/IEC ecosystem. Key related standards include:

  • ISO/IEC 18000 series: Covers foundational air interface protocols for RFID.
  • ISO/IEC 29167 (other parts): Defines specific cryptographic suites, such as AES-128, ECC-DH, and others, for implementing robust security at the air interface level.
  • ISO/IEC 15962: Governs data encoding rules and logical memory functions for RFID.
  • ISO/IEC 18031: Specifies techniques for secure random bit generation necessary for cryptographic operations.
  • GDPR and other privacy frameworks: While not ISO standards, these regulatory documents influence privacy requirements and risk management strategies for RFID systems.

Adopting ISO/IEC 29167-1:2014 ensures that RFID solutions can scale and evolve to meet future security challenges, while maintaining compatibility and interoperability with established international standards.

Buy Documents

Standard

ISO/IEC 29167-1:2014 - Information technology -- Automatic identification and data capture techniques

English language (10 pages)
sale 15% off
Preview
sale 15% off
Preview
Standard

ISO/IEC 29167-1:2014 - Information technology — Automatic identification and data capture techniques — Part 1: Security services for RFID air interfaces/6/2014

Release Date:06-Aug-2014
English language (10 pages)
sale 15% off
Preview
sale 15% off
Preview

Get Certified

Connect with accredited certification bodies for this standard

BSI Group

BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

UKAS United Kingdom Verified

NYCE

Mexican standards and certification body.

EMA Mexico Verified

Sponsored listings

Frequently Asked Questions

ISO/IEC 29167-1:2014 is a standard published by the International Organization for Standardization (ISO). Its full title is "Information technology — Automatic identification and data capture techniques — Part 1: Security services for RFID air interfaces". This standard covers: ISO/IEC 29167-1:2014 defines the architecture for security services for the ISO/IEC 18000 air interfaces standards for radio frequency identification (RFID) devices. Its purpose is to provide a common technical specification for optional security services for RFID devices that may be used by ISO committees developing RFID application standards. ISO/IEC 29167-1:2014 defines various security features called security mechanisms that can be implemented by a tag depending on the application. A tag may support one, a subset, or all of the specified security mechanisms. For an interrogator it is possible to get information about the security mechanisms that are actually implemented and supported by a tag. Moreover, it has been considered that adding new security mechanisms remains possible. Besides signalling the presence of certain security services, further details of the mechanisms such as utilized encryption algorithm and key length also need to be specified and accessible. ISO/IEC 29167-1:2014 defines the requirements for crypto suites defined in further parts of ISO/IEC 29167 and furthermore defines how crypto suites identifiers are assigned to the various parts of ISO/IEC 29167.

ISO/IEC 29167-1:2014 defines the architecture for security services for the ISO/IEC 18000 air interfaces standards for radio frequency identification (RFID) devices. Its purpose is to provide a common technical specification for optional security services for RFID devices that may be used by ISO committees developing RFID application standards. ISO/IEC 29167-1:2014 defines various security features called security mechanisms that can be implemented by a tag depending on the application. A tag may support one, a subset, or all of the specified security mechanisms. For an interrogator it is possible to get information about the security mechanisms that are actually implemented and supported by a tag. Moreover, it has been considered that adding new security mechanisms remains possible. Besides signalling the presence of certain security services, further details of the mechanisms such as utilized encryption algorithm and key length also need to be specified and accessible. ISO/IEC 29167-1:2014 defines the requirements for crypto suites defined in further parts of ISO/IEC 29167 and furthermore defines how crypto suites identifiers are assigned to the various parts of ISO/IEC 29167.

ISO/IEC 29167-1:2014 is classified under the following ICS (International Classification for Standards) categories: 35.040 - Information coding; 35.040.50 - Automatic identification and data capture techniques. The ICS classification helps identify the subject area and facilitates finding related standards.

ISO/IEC 29167-1:2014 has the following relationships with other standards: It is inter standard links to ISO/IEC 29167-1:2012. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.

ISO/IEC 29167-1:2014 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


INTERNATIONAL ISO/IEC
STANDARD 29167-1
Second edition
2014-08-15
Information technology — Automatic
identification and data capture
techniques —
Part 1:
Security services for RFID air
interfaces
Technologies de l’information — Techniques automatiques
d’identification et de capture de données —
Partie 1: Services de sécurité pour les interfaces radio RFID
Reference number
©
ISO/IEC 2014
© ISO/IEC 2014
All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized otherwise in any form
or by any means, electronic or mechanical, including photocopying, or posting on the internet or an intranet, without prior
written permission. Permission can be requested from either ISO at the address below or ISO’s member body in the country of
the requester.
ISO copyright office
Case postale 56 • CH-1211 Geneva 20
Tel. + 41 22 749 01 11
Fax + 41 22 749 09 47
E-mail copyright@iso.org
Web www.iso.org
Published in Switzerland
ii © ISO/IEC 2014 – All rights reserved

Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Conformance . 1
3 Normative references . 1
4 Terms and definitions, symbols, and abbreviated terms . 2
4.1 Terms and definitions . 2
4.2 Symbols and abbreviated terms. 2
5 Safeguarding personal privacy and data . 2
5.1 Motivation . 2
5.2 Features of this International Standard . 2
5.3 Safeguarding personal privacy and data on the tag . 3
5.4 Implications of security . 3
6 Security mechanisms . 4
6.1 General . 4
6.2 Untraceability . . 4
6.3 Physical mechanisms . 5
6.4 Cryptographic mechanisms . 5
6.5 Cryptographic suites . 5
7 Discovery mechanisms . 5
8 File management mechanisms . 5
9 Assignment of Crypto Suite Indicators (CSI) . 6
9.1 Relation of CSI and part number . 6
9.2 Example for CSI of an ISO/IEC 29167-n . 7
9.3 Example for CSI of ISO/IEC 18000-63 . 7
9.4 Sources for Crypto Suite Indicators . 7
9.5 Increase number of CSIs for ISO/IEC 29167 . 8
10 Crypto suite template . 8
Bibliography . 9
© ISO/IEC 2014 – All rights reserved iii

Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical
activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international
organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the
work. In the field of information technology, ISO and IEC have established a joint technical committee,
ISO/IEC JTC 1.
The procedures used to develop this document and those intended for its further maintenance are
described in the ISO/IEC Directives, Part 1. In particular the different approval criteria needed for the
different types of ISO documents should be noted. This document was drafted in accordance with the
editorial rules of the ISO/IEC Directives, Part 2 (see www.iso.org/directives).
Attention is drawn to the possibility that some of the elements of this document may be the subject
of patent rights. ISO and IEC shall not be held responsible for identifying any or all such patent rights.
Details of any patent rights identified during the development of the document will be in the Introduction
and/or on the ISO list of patent declarations received (see www.iso.org/patents).
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation on the meaning of ISO specific terms and expressions related to conformity
assessment, as well as information about ISO’s adherence to the WTO principles in the Technical Barriers
to Trade (TBT) see the following URL: Foreword - Supplementary information
The committee responsible for this document is ISO/IEC JTC 1, Information technology, Subcommittee
SC 31, Automatic identification and data capture techniques.
This second edition cancels and replaces the first edition (ISO/IEC 29167-1:2012) which has been
technically revised.
ISO/IEC 29167 consists of the following parts, under the general title Information technology — Automatic
identification and data capture techniques:
— Part 1: Security services for RFID air interfaces
— Part 10: Crypto suite AES-128 security services for air interface communications
— Part 11: Air interface for security services — Crypto suite PRESENT-80
— Part 12: Crypto suite ECC-DH security services for air interface communication
— Part 13: Air interface for security services — Crypto suite Grain-128A
— Part 14: Air interface for security services — Crypto suite AES OFB
— Part 15: Air interface for security services — Crypto suite XOR
— Part 16: Air interface for security services crypto suite ECDSA-ECDH
— Part 17: Air interface for security services crypto suite cryptoGPS
— Part 19: Air interface for security services crypto suite RAMON
iv © ISO/IEC 2014 – All rights reserved

Introduction
ISO/IEC 29167 describes security as applicable for ISO/IEC 18000. ISO/IEC 29167 is an optional extension
to the ISO/IEC 18000 air interfaces.
The ISO/IEC 18000 series of International Standards on radio frequency identification (RFID) for item
management does not offer strong security of the tag and interrogator data and identity. For example,
the unique item identifiers (UII) of tags are typically transmitted to every other device in the RF field
and can thus be easily tracked. Additionally, sensitive data such as passwords are typically transmitted
over RF without encryption and can easily be intercepted. Moreover, utilized passwords may be short
in length. ISO/IEC 29167 fulfills the need for applications requiring effective security in the handling of
sensitive information including the unauthorized interception and tracking of data and devices.
ISO/IEC 29167 covers the crypto suites for interrogators and tags that have security mechanisms on
board. ISO/IEC 29167 only applies to tags that perform the computations that are required for the
security mechanisms. Tag-to-tag communication is not excluded.
ISO/IEC 29167 covers a number of cryptographic suites designed for protecting application information
transmitted across the RFID air interface, product authentication, and protecting access to resources
on the tag. Suite implementations relative to specific ISO/IEC 18000 series RFID air interface standards,
where relevant, are described in the Annexes of each cryptographic suite. Users should be aware that they
must assess their own risk management needs for their application (e.g. amount of necessary security
features, management of keys, etc.) in order to determine the appropriate suite for implementation.
This part of ISO/IEC 29167 describes a framework to implement security mechanisms used in an RFID
system. The other parts of ISO/IEC 29167 specify individual crypto suites.
© ISO/IEC 2014 – All rights reserved v

INTERNATIONAL STANDARD ISO/IEC 29167-1:2014(E)
Information technology — Automatic identification and
data capture techniques —
Part 1:
Security services for RFID air interfaces
1 Scope
This part of ISO/IEC 29167 defines the architecture for security services for the ISO/IEC 18000 air
interfaces standards for radio frequency identification (RFID) devices. Its purpose is to provide a
common technical specification for optional security services for RFID devices that may be used by ISO
committees developing RFID application standards.
This part of ISO/IEC 29167 defines various security features called security mechanisms that can
be implemented by a tag depending on the application. A tag may support one, a subset, or all of the
specified security mechanisms. For an interrogator, it is possible to get information about the security
mechanisms that are actually implemented and supported by a tag. Moreover, it has been considered that
adding new security mechanisms remains possible. Besides signalling the presence of certain security
services, further details of the mechanisms such as utilized encryption algorithm and key length also
need to be specified and accessible.
This part of ISO/IEC 29167 defines the requirements for crypto suites defined in further parts of this
International Standard and, furthermore, defines how crypto suites identifiers are assigned to the
various parts of this International Standard.
2 Conformance
In general, it is assumed that all requirements defined in this part of ISO/IEC 29167 shall be fulfilled.
A tag is compliant to this part of ISO/IEC 29167 if it supports one or more of the security mechanisms as
defined in this part of ISO/IEC 29167.
An interrogator is compliant to this part of ISO/IEC 29167 if it supports one or more of the security
mechanisms as defined in this part of ISO/IEC 29167.
The discovery mechanisms are mandatory for interoperability.
3 Normative references
The following documents, in whole or in part, are normatively referenced in this document and are
indispensable for its application. For dated references, only the edition cited applies. For undated
references, the latest edition of the referenced document (including any amendments) applies.
ISO/IEC 19762 (all parts), Information technology — Automatic identification and data capture (AIDC)
techniques — Harmonized vocabulary
© ISO/IEC 2014 – All rights reserved 1

4 Terms and definitions, symbols, and abbreviated terms
4.1 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO/IEC 19762 (all parts) and the
following apply.
4.1.1
crypto suite
module for secure data handling that can be utilized by multiple air interfaces due to its modularity
4.2 Symbols and abbreviated terms
PRNG pseudo random generator
TRNG true random generator
5 Safeguarding personal privacy and data
5.1 Motivation
RFID technology enables the processing of data without physical contact or visible interaction between
the interrogator and the tag. Application of the technology can deliver numerous economic and societal
benefits.
RFID applications hold the potential to transfer data relating to an identified or identifiable person who
is being identified directly or indirectly. Furthermore, the potential exists for this technology to be used
to monitor an individual through his/her possession of one or more items that contain a unique RFID
item number. This interaction can happen without the individual concerned being aware of it.
The functionality offered by ISO/IEC 29167 allows RFID applications to provide privacy, integrity,
authenticity and confidentiality of the data on the tag. This functionality includes organization of data
and access control.
ISO/IEC 29167, in combination with ISO/IEC 18000, addresses issues of privacy and security related to
the use of RFID for Item Management. This part of ISO/IEC 29167 provides an overview, while details
will be described in the specific parts of ISO/IEC 29167 in combination with the corresponding parts of
ISO/IEC 18000.
ISO/IEC 29167 extends ISO/IEC 18000 with the following features:
— untraceability;
— authenticity;
— secure access to data and functions,
— encryption.
5.2 Features of this International Standard
The tag features and air interface commands in ISO/IEC 29167 enable the implementation of the
following features in an RFID system:
— Untraceability: by putting the tag in a special mode (called untraceability mode) where the RFID tag
hides all or part of its identity.
2 © ISO/IEC 2014 – All rights reserved

— Certify authenticity: by using one or more air interface commands a tag can produce a certificate of
authenticity. Verification of this certificate may require additional features such as
...


INTERNATIONAL ISO/IEC
STANDARD 29167-1
Second edition
2014-08-15
Information technology — Automatic
identification and data capture
techniques —
Part 1:
Security services for RFID air
interfaces
Technologies de l’information — Techniques automatiques
d’identification et de capture de données —
Partie 1: Services de sécurité pour les interfaces radio RFID
Reference number
©
ISO/IEC 2014
© ISO/IEC 2014
All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized otherwise in any form
or by any means, electronic or mechanical, including photocopying, or posting on the internet or an intranet, without prior
written permission. Permission can be requested from either ISO at the address below or ISO’s member body in the country of
the requester.
ISO copyright office
Case postale 56 • CH-1211 Geneva 20
Tel. + 41 22 749 01 11
Fax + 41 22 749 09 47
E-mail copyright@iso.org
Web www.iso.org
Published in Switzerland
ii © ISO/IEC 2014 – All rights reserved

Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Conformance . 1
3 Normative references . 1
4 Terms and definitions, symbols, and abbreviated terms . 2
4.1 Terms and definitions . 2
4.2 Symbols and abbreviated terms. 2
5 Safeguarding personal privacy and data . 2
5.1 Motivation . 2
5.2 Features of this International Standard . 2
5.3 Safeguarding personal privacy and data on the tag . 3
5.4 Implications of security . 3
6 Security mechanisms . 4
6.1 General . 4
6.2 Untraceability . . 4
6.3 Physical mechanisms . 5
6.4 Cryptographic mechanisms . 5
6.5 Cryptographic suites . 5
7 Discovery mechanisms . 5
8 File management mechanisms . 5
9 Assignment of Crypto Suite Indicators (CSI) . 6
9.1 Relation of CSI and part number . 6
9.2 Example for CSI of an ISO/IEC 29167-n . 7
9.3 Example for CSI of ISO/IEC 18000-63 . 7
9.4 Sources for Crypto Suite Indicators . 7
9.5 Increase number of CSIs for ISO/IEC 29167 . 8
10 Crypto suite template . 8
Bibliography . 9
© ISO/IEC 2014 – All rights reserved iii

Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical
activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international
organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the
work. In the field of information technology, ISO and IEC have established a joint technical committee,
ISO/IEC JTC 1.
The procedures used to develop this document and those intended for its further maintenance are
described in the ISO/IEC Directives, Part 1. In particular the different approval criteria needed for the
different types of ISO documents should be noted. This document was drafted in accordance with the
editorial rules of the ISO/IEC Directives, Part 2 (see www.iso.org/directives).
Attention is drawn to the possibility that some of the elements of this document may be the subject
of patent rights. ISO and IEC shall not be held responsible for identifying any or all such patent rights.
Details of any patent rights identified during the development of the document will be in the Introduction
and/or on the ISO list of patent declarations received (see www.iso.org/patents).
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation on the meaning of ISO specific terms and expressions related to conformity
assessment, as well as information about ISO’s adherence to the WTO principles in the Technical Barriers
to Trade (TBT) see the following URL: Foreword - Supplementary information
The committee responsible for this document is ISO/IEC JTC 1, Information technology, Subcommittee
SC 31, Automatic identification and data capture techniques.
This second edition cancels and replaces the first edition (ISO/IEC 29167-1:2012) which has been
technically revised.
ISO/IEC 29167 consists of the following parts, under the general title Information technology — Automatic
identification and data capture techniques:
— Part 1: Security services for RFID air interfaces
— Part 10: Crypto suite AES-128 security services for air interface communications
— Part 11: Air interface for security services — Crypto suite PRESENT-80
— Part 12: Crypto suite ECC-DH security services for air interface communication
— Part 13: Air interface for security services — Crypto suite Grain-128A
— Part 14: Air interface for security services — Crypto suite AES OFB
— Part 15: Air interface for security services — Crypto suite XOR
— Part 16: Air interface for security services crypto suite ECDSA-ECDH
— Part 17: Air interface for security services crypto suite cryptoGPS
— Part 19: Air interface for security services crypto suite RAMON
iv © ISO/IEC 2014 – All rights reserved

Introduction
ISO/IEC 29167 describes security as applicable for ISO/IEC 18000. ISO/IEC 29167 is an optional extension
to the ISO/IEC 18000 air interfaces.
The ISO/IEC 18000 series of International Standards on radio frequency identification (RFID) for item
management does not offer strong security of the tag and interrogator data and identity. For example,
the unique item identifiers (UII) of tags are typically transmitted to every other device in the RF field
and can thus be easily tracked. Additionally, sensitive data such as passwords are typically transmitted
over RF without encryption and can easily be intercepted. Moreover, utilized passwords may be short
in length. ISO/IEC 29167 fulfills the need for applications requiring effective security in the handling of
sensitive information including the unauthorized interception and tracking of data and devices.
ISO/IEC 29167 covers the crypto suites for interrogators and tags that have security mechanisms on
board. ISO/IEC 29167 only applies to tags that perform the computations that are required for the
security mechanisms. Tag-to-tag communication is not excluded.
ISO/IEC 29167 covers a number of cryptographic suites designed for protecting application information
transmitted across the RFID air interface, product authentication, and protecting access to resources
on the tag. Suite implementations relative to specific ISO/IEC 18000 series RFID air interface standards,
where relevant, are described in the Annexes of each cryptographic suite. Users should be aware that they
must assess their own risk management needs for their application (e.g. amount of necessary security
features, management of keys, etc.) in order to determine the appropriate suite for implementation.
This part of ISO/IEC 29167 describes a framework to implement security mechanisms used in an RFID
system. The other parts of ISO/IEC 29167 specify individual crypto suites.
© ISO/IEC 2014 – All rights reserved v

INTERNATIONAL STANDARD ISO/IEC 29167-1:2014(E)
Information technology — Automatic identification and
data capture techniques —
Part 1:
Security services for RFID air interfaces
1 Scope
This part of ISO/IEC 29167 defines the architecture for security services for the ISO/IEC 18000 air
interfaces standards for radio frequency identification (RFID) devices. Its purpose is to provide a
common technical specification for optional security services for RFID devices that may be used by ISO
committees developing RFID application standards.
This part of ISO/IEC 29167 defines various security features called security mechanisms that can
be implemented by a tag depending on the application. A tag may support one, a subset, or all of the
specified security mechanisms. For an interrogator, it is possible to get information about the security
mechanisms that are actually implemented and supported by a tag. Moreover, it has been considered that
adding new security mechanisms remains possible. Besides signalling the presence of certain security
services, further details of the mechanisms such as utilized encryption algorithm and key length also
need to be specified and accessible.
This part of ISO/IEC 29167 defines the requirements for crypto suites defined in further parts of this
International Standard and, furthermore, defines how crypto suites identifiers are assigned to the
various parts of this International Standard.
2 Conformance
In general, it is assumed that all requirements defined in this part of ISO/IEC 29167 shall be fulfilled.
A tag is compliant to this part of ISO/IEC 29167 if it supports one or more of the security mechanisms as
defined in this part of ISO/IEC 29167.
An interrogator is compliant to this part of ISO/IEC 29167 if it supports one or more of the security
mechanisms as defined in this part of ISO/IEC 29167.
The discovery mechanisms are mandatory for interoperability.
3 Normative references
The following documents, in whole or in part, are normatively referenced in this document and are
indispensable for its application. For dated references, only the edition cited applies. For undated
references, the latest edition of the referenced document (including any amendments) applies.
ISO/IEC 19762 (all parts), Information technology — Automatic identification and data capture (AIDC)
techniques — Harmonized vocabulary
© ISO/IEC 2014 – All rights reserved 1

4 Terms and definitions, symbols, and abbreviated terms
4.1 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO/IEC 19762 (all parts) and the
following apply.
4.1.1
crypto suite
module for secure data handling that can be utilized by multiple air interfaces due to its modularity
4.2 Symbols and abbreviated terms
PRNG pseudo random generator
TRNG true random generator
5 Safeguarding personal privacy and data
5.1 Motivation
RFID technology enables the processing of data without physical contact or visible interaction between
the interrogator and the tag. Application of the technology can deliver numerous economic and societal
benefits.
RFID applications hold the potential to transfer data relating to an identified or identifiable person who
is being identified directly or indirectly. Furthermore, the potential exists for this technology to be used
to monitor an individual through his/her possession of one or more items that contain a unique RFID
item number. This interaction can happen without the individual concerned being aware of it.
The functionality offered by ISO/IEC 29167 allows RFID applications to provide privacy, integrity,
authenticity and confidentiality of the data on the tag. This functionality includes organization of data
and access control.
ISO/IEC 29167, in combination with ISO/IEC 18000, addresses issues of privacy and security related to
the use of RFID for Item Management. This part of ISO/IEC 29167 provides an overview, while details
will be described in the specific parts of ISO/IEC 29167 in combination with the corresponding parts of
ISO/IEC 18000.
ISO/IEC 29167 extends ISO/IEC 18000 with the following features:
— untraceability;
— authenticity;
— secure access to data and functions,
— encryption.
5.2 Features of this International Standard
The tag features and air interface commands in ISO/IEC 29167 enable the implementation of the
following features in an RFID system:
— Untraceability: by putting the tag in a special mode (called untraceability mode) where the RFID tag
hides all or part of its identity.
2 © ISO/IEC 2014 – All rights reserved

— Certify authenticity: by using one or more air interface commands a tag can produce a certificate of
authenticity. Verification of this certificate may require additional features such as
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.

Loading comments...