ISO/IEC 29167-22:2018 - SPECK crypto suite for RFID air interfaces
Overview
ISO/IEC 29167-22:2018 specifies a crypto suite based on the lightweight block cipher SPECK for radio‑frequency identification (RFID) air interface communications. The document defines how SPECK is used to provide security services (authentication, confidentiality, integrity) for devices that implement the ISO/IEC 18000 family of air interface standards. The suite supports multiple SPECK block/key size combinations and several methods of use so Tags and Interrogators can declare and implement a single option, a subset, or the full set of options.
Key facts:
- Title: Information technology - Automatic identification and data capture - Part 22: Crypto suite SPECK security services for air interface communications
- Targeted to radio air interfaces used by ISO/IEC 18000 RFID standards
- SPECK versions supported: block/key sizes include 64/96, 96/96, 64/128, 128/128, and 128/256 (as specified in the standard)
Key topics and technical requirements
- Cipher and parameters: Definition of SPECK variants and allowed block/key length options; parameter and variable definitions that align with existing air interfaces.
- Authentication methods: Tag authentication, Interrogator authentication, and mutual authentication flows (documented message/response formats and state diagrams).
- Communication protection: Methods for encapsulating and cryptographically protecting Interrogator commands and Tag replies over the air interface.
- Key management: Key table formats and key update procedures for maintaining shared symmetric keys on Tags and Interrogators.
- Conformance and obligations: Rules for declaring supported options, protocol‑specific information, state transitions, error handling, and normative test vectors.
- Supporting materials: Normative annexes include state transition tables, error handling, SPECK description, and test vectors; informative annexes provide protocol‑specific guidance.
Practical applications
- Securing RFID communication in supply chain, inventory management, asset tracking, retail, and access control systems where constrained devices require lightweight cryptography.
- Protecting air‑interface exchanges against cloning, replay, eavesdropping, and unauthorized reads/writes.
- Enabling interoperable security features across Tags and Interrogators that reference ISO/IEC air interface standards.
Who should use this standard
- RFID device manufacturers and firmware developers implementing SPECK-based security on Tags and readers (Interrogators).
- System integrators and solution architects designing secure RFID deployments (logistics, retail, IoT).
- Standards committees, test labs, and certification bodies validating conformance to ISO/IEC 18000 air interfaces with SPECK security.
- Security engineers evaluating lightweight block cipher options for constrained environments.
Related standards
Note: The document includes patent‑related declarations; implementers should consult the ISO patents listing for IP considerations.