1、Information technology Telecommunications and information exchange between systems NFC Security Part 2:NFC-SEC cryptography standard using ECDH and AESTechnologies de linformation Tlinformatique Scurit NFC Partie 2:Norme de cryptographie NFC-SEC utilisant ECDH et AESINTERNATIONAL STANDARDISO/IEC1315
2、7-2Reference numberISO/IEC 13157-2:2016(E)Second edition2016-04-01 ISO/IEC 2016 ii ISO/IEC 2016 All rights reservedCOPYRIGHT PROTECTED DOCUMENT ISO/IEC 2016,Published in SwitzerlandAll rights reserved.Unless otherwise specified,no part of this publication may be reproduced or utilized otherwise in a
3、ny form or by any means,electronic or mechanical,including photocopying,or posting on the internet or an intranet,without prior written permission.Permission can be requested from either ISO at the address below or ISOs member body in the country of the requester.ISO copyright officeCh.de Blandonnet
4、 8 CP 401CH-1214 Vernier,Geneva,SwitzerlandTel.+41 22 749 01 11Fax+41 22 749 09 47copyrightiso.orgwww.iso.orgISO/IEC 13157-2:2016(E)ISO/IEC 13157-2:2016(E)ISO/IEC 2016 All rights reserved iii Contents Page Foreword.v Introduction.vi 1 Scope.1 2 Conformance.1 3 Normative references.1 4 Terms and defi
5、nitions.2 5 Conventions and notations.2 5.1 Concatenation.2 5.2 Hexadecimal numbers.2 6 Acronyms.2 7 General.3 8 Protocol Identifier(PID).3 9 Primitives.3 9.1 Key agreement.4 9.1.1 Curve P-192.4 9.1.2 EC Key Pair Generation Primitive.4 9.1.3 EC Public key validation.4 9.1.4 ECDH secret value derivat
6、ion Primitive.4 9.1.5 Random nonces.4 9.2 Key Derivation Functions.5 9.2.1 KDF for the SSE.5 9.2.2 KDF for the SCH.5 9.3 Key Usage.5 9.4 Key Confirmation.6 9.4.1 Key confirmation tag generation.6 9.4.2 Key confirmation tag verification.6 9.5 Data Encryption.6 9.5.1 Initial value of counter(IV).6 9.5
7、.2 Encryption.6 9.5.3 Decryption.7 9.6 Data Integrity.7 9.6.1 Protect data integrity.7 9.6.2 Check data integrity.7 9.7 Message Sequence Integrity.7 10 Data Conversions.7 10.1 Integer-to-Octet-String Conversion.7 10.2 Octet-String-to-Integer Conversion.7 10.3 Point-to-Octet-String Conversion.8 10.4
8、Octet-String-to-Point Conversion.8 11 SSE and SCH service invocation.8 11.1 Pre-requisites.9 11.2 Key Agreement.10 11.2.1 Sender(A)Transformation.10 11.2.2 Recipient(B)Transformation.10 11.3 Key Derivation.11 11.3.1 Sender(A)Transformation.11 ISO/IEC 13157-2:2016(E)iv ISO/IEC 2016 All rights reserve
9、d 11.3.2 Recipient(B)Transformation.11 11.4 Key Confirmation.11 11.4.1 Sender(A)Transformation.11 11.4.2 Recipient(B)Transformation.12 12 SCH data exchange.12 12.1 Preparation.13 12.2 Data Exchange.13 12.2.1 Send.13 12.2.2 Receive.13 Annex A(normative)AES-XCBC-PRF-128 and AES-XCBC-MAC-96 algorithms.
10、15 A.1 AES-XCBC-PRF-128.15 A.2 AES-XCBC-MAC-96.15 Annex B(normative)Fields sizes.16 Annex C(informative)Informative references.17 ISO/IEC 13157-2:2016(E)ISO/IEC 2016 All rights reserved v Foreword ISO(the International Organization for Standardization)and IEC(the International Electrotechnical Commi
11、ssion)form the specialized system for worldwide standardization.National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established by the respective organization to deal with particular fields of technical activity.ISO an
12、d IEC technical committees collaborate in fields of mutual interest.Other international organizations,governmental and non-governmental,in liaison with ISO and IEC,also take part in the work.In the field of information technology,ISO and IEC have established a joint technical committee,ISO/IEC JTC 1
13、.The procedures used to develop this document and those intended for its further maintenance are described in the ISO/IEC Directives,Part 1.In particular the different approval criteria needed for the different types of document should be noted.This document was drafted in accordance with the editor
14、ial rules of the ISO/IEC Directives,Part 2(see www.iso.org/directives).Attention is drawn to the possibility that some of the elements of this document may be the subject of patent rights.ISO and IEC shall not be held responsible for identifying any or all such patent rights.Details of any patent ri
15、ghts identified during the development of the document will be in the Introduction and/or on the ISO list of patent declarations received(see www.iso.org/patents).Any trade name used in this document is information given for the convenience of users and does not constitute an endorsement.For an expl
16、anation on the meaning of ISO specific terms and expressions related to conformity assessment,as well as information about ISOs adherence to the WTO principles in the Technical Barriers to Trade(TBT)see the following URL:Foreword-Supplementary information ISO/IEC 13157-2 was prepared by Ecma International(as ECMA-386)and was adopted,under a special“fast-track procedure”,by Joint Technical Committee ISO/IEC JTC 1,Information technology,in parallel with its approval by national bodies of ISO and I