Overview
ISO/IEC 15149-4:2016 - Information technology - Telecommunications and information exchange between systems - Magnetic field area network (MFAN) - Part 4: Security Protocol for Authentication - specifies the authentication security protocol used in MFANs. MFANs provide reliable wireless communication (and support wireless power transfer services) in harsh environments. This part defines the MFAN security (MFSec) authentication exchange, message formats at the MAC layer, and related network functions and status elements required for mutual authentication between coordinator and node.
Key topics and technical requirements
- Scope: Authentication protocol for MFAN (mutual authentication between MFAN-C and MFAN-N).
- MFSec approach: Uses an XOR-based computation for mutual authentication and lightweight operations suitable for constrained MFAN devices. The standard includes an implementation note that XOR alone is weak if used with repeating keys.
- Pre-shared key (PSK): A PSK of 8 octets is required by both coordinator and node prior to authentication. The standard does not define PSK generation or key-update mechanisms (key update is out of scope / not supported).
- Message exchange: Authentication uses a three-step exchange: Authentication Request (AuRq), Authentication Response (AuRs), and Authentication Response Confirmation (AuRc) with fields such as SRNc, SORNc, RNc, RNn and UID.
- Random numbers and operations: Both coordinator and node generate 8‑octet random numbers (RNc, RNn). Computations combine RN, UID, a fixed manufacturer constant O, PSK, and bit-wise rotations as specified.
- MAC layer and payload: The standard specifies MAC layer frame formats, frame types and payload formats for request/response/confirmation messages.
- Network elements & functions: References time, physical and addressing elements (defined in ISO/IEC 15149-3 and -1), request/response/confirmation periods, and simple key-generation steps.
- Security considerations: Annex A provides guidance and warnings about the security properties and limitations of the XOR-based technique and general threats applicable to MFAN (confidentiality, integrity, authentication).
Practical applications
- Secure authentication for MFAN deployments in industrial, sensor, or harsh-environment settings where magnetic-field communication or wireless power transfer is used.
- Lightweight mutual authentication for constrained devices (sensors, actuators, relays) that require low-complexity crypto operations.
- Use in MFAN-based systems for industrial IoT, smart metering, and localized wireless power/control networks where standard MFAN protocols (air interface, in-band control, relay) are implemented.
Who should use this standard
- Device manufacturers and firmware developers implementing MFAN coordinators and nodes.
- System integrators and solution architects designing secure MFAN deployments.
- Standards and compliance engineers evaluating MFAN authentication mechanisms and interoperability.
Related standards
Keywords: ISO/IEC 15149-4:2016, MFAN, MFSec, magnetic field area network, authentication protocol, PSK, mutual authentication, MAC frame format, wireless power transfer.