General Information

Abstract

Status
Not Published
Current Stage
6000 - International Standard under publication
Start Date
06-Aug-2026
Completion Date
29-Aug-2026

Buy Documents

Draft

ISO/IEC 14443-4:2018/FDAmd 3 - Cards and security devices for personal identification — Contactless proximity objects — Part 4: Transmission protocol — Amendment 3: Relay attack protection mechanisms

Release Date:27-May-2026
English language (5 pages)
sale 15% off
sale 15% off
Draft

REDLINE ISO/IEC 14443-4:2018/FDAmd 3 - Cards and security devices for personal identification — Contactless proximity objects — Part 4: Transmission protocol — Amendment 3: Relay attack protection mechanisms

Release Date:27-May-2026
English language (5 pages)
sale 15% off
sale 15% off

Overview

ISO/IEC 14443-4:2018/Amd 3 is an amendment to the international standard for contactless proximity identification cards and security devices, specifically focusing on the transmission protocol's relay attack protection mechanisms. Published jointly by ISO and IEC under the JTC 1/SC 17 technical committee, this amendment introduces specifications and procedural enhancements that strengthen the protection of contactless cards, such as smart cards and electronic passports, against relay attacks.

By refining the transmission protocol and introducing a timed nonce exchange (TNE) procedure, this amendment addresses the growing need for enhanced security in electronic identification and contactless payment systems.

Key Topics

  • Relay Attack Protection Mechanisms: The amendment adds protocols designed to help devices detect and defend against relay attacks, where an attacker tricks a card reader and card into communicating over extended distances.
  • Timed Nonce Exchange (TNE): The core addition in this amendment is the TNE procedure, allowing proximity coupling devices (PCDs) and proximity integrated circuit cards (PICCs) to securely exchange nonces (random numbers) and response timing data to verify proximity.
  • Protocol Refinements: Clarifications and updates to S-block exchanges, frame handling, the use of Hamming control matrices, and other protocol elements to ensure interoperability and correct implementation.
  • Compatibility: Guidance is provided on maintaining interoperability with legacy systems, ensuring that new security features can be introduced while supporting existing deployments.

Applications

The relay attack protection mechanisms introduced in ISO/IEC 14443-4:2018/Amd 3 provide significant practical benefits, especially in sectors where secure personal identification and authentication are critical. Key applications include:

  • Electronic Passports and Identity Cards: Improved protection against relay attacks enhances trust in secure border control and electronic ID verification systems.
  • Contactless Payment Cards: The TNE mechanism helps detect fraudulent attempts to relay transactions, contributing to safer payment environments for consumers and merchants.
  • Access Control Systems: Security is strengthened in applications such as secure facility access, public transportation, and event ticketing.
  • Healthcare Cards: Protects personal health data by reducing the risk of unauthorized access through relay attacks.
  • Enterprise and Government Security: Organizations using contactless badges and secure identification benefit from reduced risk of credential cloning or misuse.

Related Standards

For full implementation and to ensure comprehensive security, ISO/IEC 14443-4:2018/Amd 3 should be considered alongside other relevant international standards:

  • ISO/IEC 14443 Series: Covers the overall structure for proximity cards, including physical characteristics (Part 1), radio frequency interface (Part 2), initialization and anti-collision (Part 3), and transmission protocol (Part 4).
  • ISO/IEC 7816 Series: Specifies physical and electrical standards for integrated circuit cards.
  • ISO/IEC 18013: Standards related to document and driver’s licenses for personal identification.
  • ISO/IEC 9798: Techniques for entity authentication, including cryptographic protocols.

Conclusion

ISO/IEC 14443-4:2018/Amd 3 delivers vital advancements for the security of contactless identification and payment systems by introducing robust relay attack protection mechanisms. Its specifications, such as the timed nonce exchange, are critical for any organization developing or deploying secure contactless solutions. By adhering to this amendment and related standards, implementers can ensure stronger safeguards against evolving threats in the smart card and security device ecosystem. For the latest official versions and guidance, consult ISO or national standardization bodies.

Relations

Effective Date
25-Mar-2023

Buy Documents

Draft

ISO/IEC 14443-4:2018/FDAmd 3 - Cards and security devices for personal identification — Contactless proximity objects — Part 4: Transmission protocol — Amendment 3: Relay attack protection mechanisms

Release Date:27-May-2026
English language (5 pages)
sale 15% off
sale 15% off
Draft

REDLINE ISO/IEC 14443-4:2018/FDAmd 3 - Cards and security devices for personal identification — Contactless proximity objects — Part 4: Transmission protocol — Amendment 3: Relay attack protection mechanisms

Release Date:27-May-2026
English language (5 pages)
sale 15% off
sale 15% off

Get Certified

Connect with accredited certification bodies for this standard

BSI Group

BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

UKAS United Kingdom Verified

NYCE

Mexican standards and certification body.

EMA Mexico Verified

Sponsored listings

Frequently Asked Questions

ISO/IEC 14443-4:2018/Amd 3 is a draft published by the International Organization for Standardization (ISO). Its full title is "Cards and security devices for personal identification — Contactless proximity objects — Part 4: Transmission protocol — Amendment 3: Relay attack protection mechanisms". This standard covers: Cards and security devices for personal identification — Contactless proximity objects — Part 4: Transmission protocol — Amendment 3: Relay attack protection mechanisms

Cards and security devices for personal identification — Contactless proximity objects — Part 4: Transmission protocol — Amendment 3: Relay attack protection mechanisms

ISO/IEC 14443-4:2018/Amd 3 is classified under the following ICS (International Classification for Standards) categories: 35.240.15 - Identification cards. Chip cards. Biometrics. The ICS classification helps identify the subject area and facilitates finding related standards.

ISO/IEC 14443-4:2018/Amd 3 has the following relationships with other standards: It is inter standard links to ISO/IEC 14443-4:2018. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.

ISO/IEC 14443-4:2018/Amd 3 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


FINAL DRAFT
Amendment
ISO/IEC
14443-4:2018/
FDAM 3
ISO/IEC JTC 1/SC 17
Cards and security devices
Secretariat: BSI
for personal identification —
Voting begins on:
Contactless proximity objects —
2026-06-10
Part 4:
Voting terminates on:
2026-08-05
Transmission protocol
AMENDMENT 3: Relay attack
protection mechanisms
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
IN ADDITION TO THEIR EVALUATION AS
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO­
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
Reference number
ISO/IEC 14443­4:2018/FDAM 3:2026(en) © ISO/IEC 2026

FINAL DRAFT
ISO/IEC 14443-4:2018/FDAM 3:2026(en)
Amendment
ISO/IEC
14443-4:2018/
FDAM 3
ISO/IEC JTC 1/SC 17
Cards and security devices
Secretariat: BSI
for personal identification —
Voting begins on:
Contactless proximity objects —
Part 4:
Voting terminates on:
Transmission protocol
AMENDMENT 3: Relay attack
protection mechanisms
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
© ISO/IEC 2026
IN ADDITION TO THEIR EVALUATION AS
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO­
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
or ISO’s member body in the country of the requester.
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland Reference number
ISO/IEC 14443­4:2018/FDAM 3:2026(en) © ISO/IEC 2026

© ISO/IEC 2026 – All rights reserved
ii
ISO/IEC 14443-4:2018/FDAM 3:2026(en)
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical activity.
ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations,
governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of document should be noted. This document was drafted in accordance with the editorial rules of the ISO/
IEC Directives, Part 2 (see www.iso.org/directives or www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the
use of (a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any
claimed patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not
received notice of (a) patent(s) which may be required to implement this document. However, implementers
are cautioned that this may not represent the latest information, which may be obtained from the patent
database available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall not be held
responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 17, Cards and security devices for personal identification.
A list of all parts in the ISO/IEC 14443 series can be found on the ISO and IEC websites.
Any feedback or questions on this document should be directed to the user’s national standards
body. A complete listing of these bodies can be found at www.iso.org/members.html and
www.iec.ch/national-committees.

© ISO/IEC 2026 – All rights reserved
iii
ISO/IEC 14443-4:2018/FDAM 3:2026(en)
Cards and security devices for personal identification —
Contactless proximity objects —
Part 4:
Transmission protocol
AMENDMENT 3: Relay attack protection mechanisms

4.1
Replace “A Hamming control bits generation matrix (6 rows, 56 columns)” by “A Hamming control generation
matrix (6 rows, 56 columns)”.
4.1
Replace “ 64-bit vector ( with no padding bits)” by “ 62-bit vector ( with no padding bits)”.
5.1
Replace the last paragraph with: “The RFU handling specified in ISO/IEC 14443-3:2018, 5.3 applies for
Clause 5, unless specified otherwise.”
5.4.2
Add the following after the second paragraph: “A PICC receiving (b4 to b1) <> (0001)b and/or receiving
(b8 to b6) <> (000)b may apply 5.7.2.2 (b).”
7.4
Replace the last paragraph with: “The temporary FWT applies only until the next block (valid or not) has
been received by the PCD or a FWT time-out occurs.
NOTE Unless the PICC requests again for a waiting time extension after reception of an R(NAK), the definedFWT
is no more extended.”
7.6.1
Replace the second paragraph with: “The PCD may initiate an exchange of S(PARAMETERS) after
reception of any PICC block without transmission error or FWT time-out, also during PCD chaining or PICC
chaining before it continues block exchange with the new parameter settings (if modified by the PCD and
acknowledged by the PICC).
To ensure interoperability with legacy PCDs and PICCs, the following behaviour is accepted until 2032: the
PCD may initiate an exchange of S(PARAMETERS) at any time also during PCD chaining or PICC chaining or
error handling, before it continues block exchange with the new parameter settings (if modified by the PCD
and acknowledged by the PICC).”
In Table 5, row 1, column 4, replace “Tables 6 and 7, in any order” with “Tables 6, 7 and 8, in any order unless
otherwise specified”.
7.6.3
© ISO/IEC 2026 – All rights reserved
ISO/IEC 14443-4:2018/FDAM 3:2026(en)
Delete the words "Assertion: PICC maxi" in the top of Figure 23.
7.6.5.1
Replace Rule 3 with: “S-blocks are only used in pairs. An S(.) request block shall always be followed by
an S(.) response block (see 7.4, 7.6.1 and Clause 8) except for PICCs
...


2025-12-12
ISO/IEC 14443-4.2:2018/DAMFDAmd 3:2026(en)
ISO/IEC JTC 1/SC 17
Secretariat: BSI
Date: 2026-05-26
Cards and security devices for personal identification — Contactless
proximity objects —
—
Part 4:
Transmission protocol —
Amendment
AMENDMENT 3: Relay attack protection mechanisms
FDIS stage
ISO/IEC 14443-4:2018/FDAmd 3(en)
© ISO/IEC 2026
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication
may be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying,
or posting on the internet or an intranet, without prior written permission. Permission can be requested from either ISO
at the address below or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: + 41 22 749 01 11
Fax: +41 22 749 09 47
EmailE-mail: copyright@iso.org
Website: www.iso.org
Published in Switzerland
© ISO/IEC 2026 – All rights reserved
ii
ISO/IEC 14443-4:2018/FDAmd 3(en)
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are members
of ISO or IEC participate in the development of International Standards through technical committees
established by the respective organization to deal with particular fields of technical activity. ISO and IEC
technical committees collaborate in fields of mutual interest. Other international organizations, governmental
and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types of
document should be noted. This document was drafted in accordance with the editorial rules of the ISO/IEC
Directives, Part 2 (see www.iso.org/directives or www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the use of
(a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any claimed
patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not received
notice of (a) patent(s) which may be required to implement this document. However, implementers are
cautioned that this may not represent the latest information, which may be obtained from the patent database
available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall not be held responsible for
identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 17, Cards and security devices for personal identification.
A list of all parts in the ISO/IEC 14443 series can be found on the ISO and IEC websites.
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www.iso.org/members.html and www.iec.ch/national-
committees.
© ISO/IEC 2026 – All rights reserved
iii
ISO/IEC 14443-4:2018/FDAmd 3(en)
Cards and security devices for personal identification — Contactless
proximity objects —
—
Part 4:
Transmission protocol —
Amendment
AMENDMENT 3: Relay attack protection mechanisms

4.1
Replace “A Hamming control bits generation matrix (6 rows, 56 columns)” by “A Hamming control generation
matrix (6 rows, 56 columns)”.
4.1
Replace “ “ 64-bit vector ( ( with no padding bits)” by “ “ 62-bit vector ( ( with no padding
bits)”.
5.1
Replace the last paragraph with: “The RFU handling specified in ISO/IEC 14443-3:2018, 5.3 applies for
Clause 5, unless specified otherwise.”
5.4.2
Add the following after the second paragraph: “A PICC receiving (b4 to b1) <> (0001)b and/or receiving
(b8 to b6) <> (000)b may apply 5.7.2.2 (b).”
7.4
Replace the last paragraph with: “The temporary FWT applies only until the next block (valid or not) has been
received by the PCD or a FWT time-out occurs.
NOTE Unless the PICC requests again for a waiting time extension after reception of an R(NAK), the defined
FWTdefinedFWT is no more extended.”
7.6.1
Replace the second paragraph with: “The PCD may initiate an exchange of S(PARAMETERS) after reception of
any PICC block without transmission error or FWT time-out, also during PCD chaining or PICC chaining before
it continues block exchange with the new parameter settings (if modified by the PCD and acknowledged by
the PICC).
To ensure interoperability with legacy PCDs and PICCs, the following behaviour is accepted until 2032: the
PCD may initiate an exchange of S(PARAMETERS) at any time also during PCD chaining or PICC chaining or
error handling, before it continues block exchange with the new parameter settings (if modified by the PCD
and acknowledged by the PICC).”
© ISO/IEC 2026 – All rights reserved
ISO/IEC 14443-4:2018/FDAmd 3(en)
In Table 5, row 1, column 4, replace “Tables 6 and 7, in any order” with “Tables 6, 7 and 8, in any order unless
otherwise specified”.
7.6.3
Delete the words "Assertion: PICC maxi" in the top of Figure 23.
7.6.5.1
Replace Rule 3 with: “S-blocks are only used in pairs. An S(.) request block shall always be followed by an
S(.) response block (see 7.4, 7.6.1 and Clause 8) except for PICCs not supporting S(PARAMETERS).
Consequently, after a PICC S(WTX) request block, the PCD shall not send an S(…) request block before sending
its S(WTX) response block.”
7.6.5.2
Add “unless otherwise specified”, at the end of rule 8.
10.1
Replace the first sentence by: "Frames with error correction as specified in 10.2 and 10.3 shall be used after
their activation as specified in 10.5.”
10.4.4
Replace "Hamming control bits generation matrix" by "Hamming control generation matrix”.
10.5
Add a new Clause 11 after subclause 10.5.
11  Timed nonce exchange
11.1  General
The timed nonce exchange (TNE) is a method whereby the PCD and the PICC exchange two nonces and provide
information of the response tim
...