Overview
ISO/IEC 29167-19:2019 specifies the RAMON (Rabin–Montgomery) crypto suite for air interface communications in RFID systems. Intended as a common, reference crypto suite for the ISO/IEC 18000 family of RFID air interface standards, this document defines authentication, cipher usage, session key derivation and secure messaging for Tags and Interrogators. The second edition updates key management to support extended key lengths and clarifies cipher and TLV structures.
Keywords: ISO/IEC 29167-19:2019, RAMON, Rabin-Montgomery, RFID security, air interface, ISO/IEC 18000.
Key topics and technical requirements
- Crypto suite definition: Formal description of the RAMON cipher and supported cryptographic operations aligned with RFID air interfaces.
- Authentication methods: Procedures for Tag identification and symmetric mutual authentication, including message formats and error responses.
- Key management and formats: Definitions for IID/SID, used keys, personalization, and a key table mechanism.
- Session key derivation: KDF (counter mode) and key derivation schemes for establishing session keys between Tag and Interrogator.
- Send sequence counter: Mechanisms to protect message ordering and replay resilience.
- Secure communication / secure messaging: Encoding of Read/Write commands, CBC mode explanation, padding for symmetric encryption, and secure communication commands/responses.
- Conformance and interoperability: Rules for claiming conformance; Tags and Interrogators may implement one, a subset or all options but must declare supported choices.
- Operational guidance: State diagrams, initialization/reset procedures, state transition tables, error codes, test vectors and protocol specifics (annexes).
- Extensible key lengths: Second edition permits RAMON key lengths beyond 1024 bits in 128-bit increments, with a revised mix function and separated TLV/cipher descriptions. A new TLV structure supports ASC MH10 identifiers.
Applications and practical value
- Secure identification and authentication for UHF and other RFID air interfaces in:
- Supply chain and logistics (anti-counterfeiting, provenance)
- Asset tracking and inventory control
- Access control and secure item-level tagging
- Industrial IoT devices using RFID as a secure bootstrap or identity layer
- Provides implementers with standardized message formats, test vectors and conformance rules for interoperable, secure RFID deployments.
Who should use this standard
- RFID tag and reader manufacturers, firmware developers and system integrators
- Security architects designing RFID-based authentication or secure messaging
- Standards committees and certification labs validating RFID security conformance
- Application developers in logistics, retail, healthcare and access control implementing secure RFID communications
Related standards
- ISO/IEC 18000 series (RFID air interface standards)
- Other parts of ISO 29167 (crypto suites for AIDC/RFID)
ISO/IEC 29167-19:2019 is a practical, implementer-focused standard to enable interoperable, future-proof cryptographic protection for RFID air interface communications.