Tuesday, October 5, 2010

Privacy vs. Security on the DASH7 Wireless Sensor Networking Blog

The concepts of security and privacy are related, but different, and people often confuse the two issues. SecureRF’s CEO, Louis Parks, tackles this topic in his first posting for the DASH7 Wireless Sensor Networking Blog.

His post, Privacy vs. Security, lays down a foundation on what is security versus privacy, in a general, non-specific product way.
Future postings will cover:
  • “What is security?” and describe related tools and functions.
  • How you put these tools together to create security protocols that address real world issues.
  • Security on a DASH7 platform.
  • Addressing and describing the security needs and solutions for different applications and industries of interest to the DASH7 Alliance.
Pat Burns, President of the DASH7 Alliance, starts the conversation with his posting - Introducing Louis Parks.
The DASH7 Alliance was formed to advance the use of DASH7 wireless data technology by developing extensions to the ISO 18000-7 active RFID standard, ensuring interoperability among devices, and educating the market about DASH7 technology.  SecureRF is now a member of this organization.

Monday, August 16, 2010

In the News - Mikoh

Fellow RFIDSA member, Neil Mitchell of MIKOH Corporation Limited, had an article published in the July/August issue of Miltary Embedded Systems.  It is titled  "RFID and asset authentication: Enabling true security measures," and can be viewed at http://www.mil-embedded.com/articles/id/?4787.

Wednesday, July 28, 2010

RFID Security Alliance Examines Risks

RFID Security Alliance Examines the Risks Associated with Wal-Marts Recently Announced Shift of RFID Technology from the Warehouse into its 3,750 U.S. Stores

Wal-Mart Continuing to Drive the Industry Adoption and Risk Management of RFID Tags in the Retail Market

Sausalito, CA, July 27, 2010 – With over 250 million RFID (Radio Frequency Identification) tags being put into Wal-Mart’s men’s basics, across Wal-Marts 3,750 U.S. stores, the RFID Security Alliance (“RFID SA”) has been receiving a number of inquiries from the public questioning the security and privacy of their personal information and their risks when purchasing such merchandise.

“We at the RFID SA take an active role to educate the industry and lay person of the advantages and risks associated with RFID based solutions and are deeply committed to insuring that everyone’s information remains private and secure in a well implemented RFID solution” said RFID SA Chairman Michael McCartney. He continued “In reviewing the details of this use-case we find the threat to privacy to be very low and in fact not dissimilar to that of bar codes that it is designed to replace. The removable tags are attached to the garment in the same manner as the conventional bar code tags, with a plastic or cotton loop or tie. Additionally, once removed, these tags can also be permanently disabled with a pair of scissors rendering them irrevocably unreadable so even once the tag is disposed of at the home, the tag can no longer be accessed”.

Additionally, since the information, as the RFID SA understands it, is basic inventory information used to keep track of in stock jeans and apparel items, the RFID SA seriously doubt how useful this non-personal information might be to anyone other than Wal-Mart.

At the RFID SA, we will continue to perform due diligence on this project and others to determine what is the threat level to the public’s privacy. We also will continue to educate the RFID industry on best practices and to make certain that the level of security is high enough to protect the consumer and the markets use of RFID technology. RFID can provide huge cost savings to the industry that will also be passed onto the consumer and will also allow faster and more efficient checkout and returns. While a poorly implemented system could be open to risk, the RFID SA is promoting industry best practices to insure all RFID implementations provide all the benefits with minimal risks.

About the RFID Security Alliance
The RFID Security Alliance (RFIDSA) was founded as a resource for the RFID industry, driving market education and discussion about security and privacy issues surrounding the use of RFID technologies, solutions and applications. More information about RFID SA can be found on its Web site at www.RFIDSA.com. Insights into RFID Security can be also found on the association’s blog at http://rfidsa.blogspot.com/ or contact Anna Haight at Anna.Haight@RFIDSecurityAlliance.org.

Wednesday, June 9, 2010

India Wide ID system and more at RFIDSA meeting on 6/10

At this month's RFID Security Alliance meeting Mohinder Sikka of Sensitel, Inc. will be providing information about the India Wide Identification system which is being implemented.  Q&A session to follow.

This open discussion will be followed by a RFID Security Alliance business meeting.


You are welcome to join us.

Meeting Details:
Thursday, June 10
10:00 a.m. – 11:00 a.m. PST / 1:00 p.m. – 2:00 p.m. EST

To participate:
Dial in Phone Number: 218.936.7999
Access code: 413685# (Follow the prompts)
Physical Location: QLM Consulting, Sausalito CA

Friday, May 28, 2010

First human ‘infected with computer virus’ - Another example of “spreading the fear”

Contributed by Neil Mitchell, RFIDSA Vice Chairperson

Another example of how RFID is “being connected” in negative technology reporting occurred this week from one of the respected news sources. The BBC reported on a University researcher who embedded himself with an RFID device that is used to open the doors in the university and enable his cell phone. However, the device was purposely embedded with a computer virus intended to infect other such similar implants. The fear factor is the potential spread of this computer virus between similar embedded devices in people (that happen to use RFID to communicate). Examples they have included Pace Makers and Deep Brain Stimulators that actually do not contain RFID readers. This fact was conveniently overlooked.

While a very valid topic (protecting human embedded devices from viruses), little attempt was made to distant the RFID technology as cause of the technology weakness. There are no cases of this “in the wild” today although this is a very valid topic that the RFID Security Alliance is also monitoring.

Fellow RFIDSA member and security consultant, Lukas Grunwald, pointed out that “This is the classical Riebeck scheme.” More information on RFID viruses can be found at Dr Melanie Rieback’s homepage: www.cs.vu.nl/~melanie/ and http://www.rfidvirus.org/.

The BBC’s story is here: http://news.bbc.co.uk/2/hi/technology/10158517.stm.

Tuesday, May 11, 2010

Insights into the Spring Conference Season

Members of the RFID Security Alliance have been busy attending conferences all over the globe. These attendees are going to share their insights about these recent events at our next RFIDSA meeting.

• INTERPHEX Pharmaceutical Conference - Louis Parks, CEO of SecureRF
• RFID Journal Live - Michael McCartney, QLM Consulting and Chair, RFIDSA
• United Fresh - Michael McCartney, QLM Consulting and Chair, RFIDSA
• Pan-European High Security Printing Conference - Lukas Grunwald, Neocatena

Also, Tim Downs will talk about two upcoming events:

• Smart Grid Cyber Security Summit
• Life Sciences Information Security conference

This open discussion will be followed by a RFID Security Alliance business meeting.

You are welcome to join us.

Meeting Details:
Wednesday, May 12
10:00 a.m. – 11:45 a.m. PST / 1:00 p.m. – 2:45 p.m. EST

To participate:
Dial in Phone Number: 218.936.7999
Access code: 413685# (Follow the prompts)

Physical Location: QLM Consulting, Sausalito CA

Friday, April 30, 2010

Video: The Use of RFID in Supply Chain Security

Contributed by Joanne C. Kelleher

Last week was the annual INTERPHEX Conference for pharmaceutical manufacturers and packagers. Editors of BioPharm International and Pharmaceutical Technology conducted a series of in-depth conversations with speakers, industry stakeholders and thought leaders.

RFID Security Alliance members Louis Parks, CEO of SecureRF and Bikash Chatterjee, CTO of Pharmatech Associates, along with Anthony Palermo, Director of the RFID Centre of Excellence were interviewed together about the use of RFID in supply chain security.

You can view their interview at http://interphexvideocast.com/media/index.php?vid=Bikash_Anthony_Louis.

All of the interviews conducted at INTERPHEX are at http://interphexvideocast.com/

Monday, April 12, 2010

RFIDSA at INTERPHEX 2010

Members of the RFID Security Alliance (RFIDSA) are participating in a discussion at the 2010 INTERPHEX conference titled “Securely Implementing RFID in the Pharmaceutical Supply Chain.”  The talk will be presented on Wednesday, April 21, 2010 from 2:15PM - 3:45PM at the Jacob K. Javits Center in New York, NY.

Participants include these RFIDSA members:
  • Louis Parks, President and CEO of SecureRF Corporation
  • Bikash Chatterjee, President and CTO of Pharmatech Associates Inc.

We hope you will be able to attend their session.  Not yet registered for INTERPHEX?  As a speaker, they have the ability to extend a 15% registration discount to friends and colleagues.  Go to http://www.interphex.com/speaker.  This link will access the official INTERPHEX website which contains complete event details including the full Conference program and online registration. The speaker discount has been programmed into the link and will automatically display reduced pricing when you begin the registration process.

Friday, April 9, 2010

RFIDSA at RFID Journal LIVE 2010

RFID Journal LIVE 2010 is next week, April 14-16 in Orlando, FL.

Michael McCartney, RFID Security Alliance's chairperson, will be speaking in the RFID for IT Professionals track. His talk, titled RFID Security: Potential Threats, Their Impact and Solutions, will be presented on 4/14 at 11:30 am.

If you are going to this conference, please attend this session and introduce yourself to Michael.

Friday, March 26, 2010

Notes on InterTraffic Conference

RFIDSA's Vice Chairperson, Neil Mitchell, shared his insights about the InterTraffic Conference. 
---------------

InterTraffic was held over 4 days this month from March 23rd – 26th in Amsterdam. The show runs every 2 years and has considerably expanded from the show 2 years ago (having almost tripled in size!). It is a broad based traffic event and not solely focused on RFID or security technologies. While some portions of the show are not relevant to MIKOH and the RFID Security Alliance there are significant key parts that are.

ITS (Intelligent Traffic Systems) and Cooperative Systems which are highly relevant took up 1/3 of the show and Safety and Infrastructure that had parts that were relevant and parts that were not took up another 1/3 of the show.

Attendance was mostly European but there were significant attendance from beyond including North and South America, Asia (including Russia and China), and Australia.

Major themes from the show were:
• Increased use of video based vehicle tracking (free flow, parking, security etc). Note: Clearly video based tracking has hugely varying read rates from 65%-95%) and if to be used as a revenue generating activity is often used in addition to a technology such as RFID to fill that significant gap (unless in a more controlled environment such as parking).
• Vehicle networking and traffic management using vehicle-to-vehicle communication (of information such as speed, time, GPS location etc). There was actually a live demo around Amsterdam of this technology. RFID tags on vehicles can be part of this solution but is likely to be used only if employed for other reasons beyond just this.

While the theme of security was present, it was mostly from the point of view of vehicle security (high level tracking and monitoring) and less so the detailed issues relating to tag security.

The show was generally, highly relevant for anyone involved in Automatic Vehicle Identification (e.g. Electronic Vehicle Registration, tolling, parking etc) and a very good meeting place for customers, partners and relevant industry bodies.

Thursday, January 7, 2010

Karsten Nohl to Discuss Hacking Mifare and other 'secure' RFID on 1/13/2010

The RFID Security Alliance has changed the format of their monthly meetings and will now start with a discussion of a topic of interest. On January 13, 2010 researcher Karsten Nohl will mark the 25th anniversary month of declaring Mifare insecure by leading a discussion about Mifare and several other types of 'secure' RFID which have been broken in the meantime (HID, Legic).

Questions to be covered include:
  • How have the hacks on the Mifare transit cards impacted new projects?
  • How have existing systems been protected?
  • What is status of Mifare Plus?
  • How have other systems been broken?

Karsten bridges the three worlds of academic research, hacking, and industry. His academic research with the University of Virginia focuses on privacy protection in large networks. His hacking projects-- at H4RDW4RE in the Silicon Valley or with the CCC in Berlin--assess (and usually break) proprietary cryptography. Finally, his consulting job at McKinsey helps him understand why corporations often choose technically inferior solutions.
 
The meetings can be joined in person in California or via conference call. If you want to participate in next week's call (Wednesday, 1/13) on this topic, you are welcome to join us at 10 AM PST / 1PM EST. After this discussion and an open Q&A you can stay on the call for RFIDSA internal business topics if you wish.

Dial in Phone Number: 218.936.7999
Access code: 413685# (Follow the prompts)

RFID Security Alliance meetings are usually scheduled for the second Wednesday of each month at 10 AM PST / 1PM EST. More info about the RFID Security Alliance is at http://www.rfidsa.com/ or via the LinkedIn Group at http://www.linkedin.com/groups?gid=62849.


Contributed by Joanne C. Kelleher
RFIDSA Marketing Committee

Tuesday, December 22, 2009

RFID Readers May Become Ubiquitous

During December’s RFID Security Alliance call, there was an open discussion on the effects of RFID readers becoming ubiquitous. This frank and useful discussion posed the following questions:

What will happen when RFID Readers become embedded in common every day devices that a non-expert can use?

One examples of RFID readers becoming embedded in a common device is with the Smart Phone that many of us own today. Such speculation is not baseless and while limited to the rumor mill at this point, it seems likely that some consumer devices will start to incorporate such reader technologies in the near future. How do we know this?

On the speculative side, the rumor mills are filled with suggestions that next generation Apple iPhone may include such technology:

http://www.appleinsider.com/articles/09/11/05/report_apple_testing_rfid_swipe_support_in_iphone_prototypes.html

http://www.tuaw.com/2009/04/15/iphone-rfid-prototype-is-very-cool/

On the more fact-based side, we know that NXP semiconductors and others are developing combo chips that combine Cell Phone and RFID technology into single devices. While this does not mean a product will certainly be on the market with this functionality, it seems a high probability.

How might such multi-function devices be used?

There could be many uses. Speculating a little, one rational would be to incorporate such RFID reading capability with bar code and other sensors to allow a device to read a product ID (and other information). This would then be used to locate information about the product (through the internet via the cell phone connection), possibly including price at varying local stores as well as a combination of other on-line retailers. Why? To enable a purchase from a different location than the one were you scanned the item. Motivation for purchasing elsewhere includes price, offering a value added purchase, offering related products and their improved availability or other factors (service, support etc). The goal would be to take a small service fee for the pleasure.

Another possible usage is to turn the iPhone into a ‘digital wallet” with RFID.
http://www.9to5mac.com/node/11939

What will happen when RFID Readers are available to such users?

Phones are regularly hacked (e.g. “Jailbreaking” iPhone) or increasingly targeted for unscrupulous activities (e.g. identity theft etc). It will be no different with RFID reader enabled devices and the system and tags in question. One member suggested that applications that have value will be the first ones hacked and then hackers will pick on applications that will be fun to break or for bragging rights.


The RFID Security Alliance is looking carefully at such concerns and has decided to pull together a “Best Practices” white paper to address these concerns. Any solution must address the full spectrum of threats, RF security, physical tag security, reader security etc.

Contributed by Neil Mitchell, RFIDSA Vice Chair

Wednesday, December 9, 2009

The RFIDSA's View of the RFID Marketplace

At last week’s RFID Security Alliance meeting we had open discussions about the effects of RFID readers becoming ubiquitous and the state of the RFID marketplace.

Aim Global’s RFID Connections recently spoke with Reik Read, senior analyst for Robert W. Baird & Co., about RFID and the economy. They posted this podcast at the same time the RFIDSA was meeting and it was interesting to see that there are strong overlaps between the thoughts of our members and a leading analyst. You can read/listen to Reik’s interview here. http://www.aimglobal.org/members/news/templates/template.aspx?articleid=3613&zoneid=42.

Here are the highlights from the RFID Security Alliance marketplace discussion:
• Up to 6 months ago, RFID projects were on hold but they are now starting to pick back up.
• There is a shift from exploring RFID to problem solving, i.e. automating to reduce costs, errors and staff.
• The RFID technology is now ready for prime time and the costs of tags and readers are coming down. New products are being developed that will make implementations better: i.e. readers with higher sensitivity, multi-directional tags and more security functions.
• As the role of the U.S. Food and Drug Administration changes and becomes a fully empowered agency, they will be looking at food traceability so RFID will grow.
• Ultra Wide Band is getting more traction around sensitive equipment like in hospitals.
• Several members are seeing more overseas (rather than US) activities, especially for asset tracking.

Of course, our members continue to think that security is an significant issue related to RFID. I was glad to see Reik Read highlighted it as an important issue too.

What are your thoughts about the current RFID marketplace? We invite you to add your comments.

Contributed by Joanne Kelleher, SecureRF Corporation
RFIDSA Marketing Committee

Friday, December 4, 2009

Call for Papers: The Workshop on RFID Security 2010

Here is a call for papers.
The Workshop on RFID Security 2010 (http://www.projectice.eu/rfidsec10/index.html) is the sixth edition of a series of workshops held in Graz, Malaga, Budapest and Leuven. In 2010 it will take place in Istanbul, Turkey.

The workshop focuses on approaches to solve security and data-protection issues in advanced contactless technologies like RFID. It stresses implementation aspects imposed by resource constraints.

 
Topics of the conference include but are not limited to:
  • New applications for secure RFID systems
  • Data protection and privacy-enhancing techniques for RFID
  • Cryptographic protocols for RFID
  •     Authentication protocols
  •     Key update mechanisms
  •     Scalability issues
  • Integration of secure RFID systems
  •     Middleware and security
  •     Public-key Infrastructures
  •     Case studies
  • Resource-efficient implementation of cryptography
  •     Small-footprint hardware
  •     Low-power architectures
  • Attacks on RFID systems
  • RFID security hardware e.g. RFID with PUF, RFID Trojans, .
Important Dates:
  •  April 20, 2010 Submission Deadline
  •  May 20, 2010 Notification
  •  June 1, 2010 Final Version
  •  June 8 - 10, 2010 RFIDSec Workshop

  
More details about how to submit a paper are at http://www.projectice.eu/rfidsec10/CfP/index.html.

 
Someone from SecureRF attended this event a few years ago and found it was a mix of researchers, academics and businesses.

  
Joanne C. Kelleher
RFID Security Alliance Marketing Committee

 


 

Wednesday, November 18, 2009

Speaking Opportunity in Singapore

Hello RFIDSA members,
I received an email today that the Pharmas & Biotech Supply Chain Asia 2010 conference has an open call for speakers. This conference is being held on March 17-18, 2010 in Singapore. http://www.terrapinn.com/2010/pharmascm/index.stm

The invitation said:
"Pharmas & Biotech Supply Chain Asia 2010 will address:
- Import & export regulatory compliance
- Clinical Supply Chain
- Cold chain management and supply
- Achieving Drug Safety across the entire supply chain
- Protecting Inbound Supply Chain Through Stringent Suppliers Qualification
- Managing your logistics and distribution in Asian context
- Strategising the right demand forecasting strategy to ensure speed to market and product availability
- The essential data management technologies to drive supply chain visibility and security
- Manufacturers-Suppliers- Vendors Relationship Management: Collaborating with varies supply chain stakeholders to increase supply chain visbility and integration
- Establishing good supply chain practice in challenging market - India And China
- Packaging and labelling strategies to ensure regulatory compliance and product safety

We are now looking for industry leaders to share their expertise, experience and strategies on the above mentioned topics. Do you have an interesting case study to share? Interested to speak at the event?

Contact Stella Teo at +65 6322 2737 or email stella.teo@terrapinn.com to discuss your speaking opportunity at Pharma & Biotech Supply Chain Asia now!"


I don't know anything else about this event and it sounds like a "sponsored" speaking opportunity (i.e. you have to pay), but I thought I would pass it along in case anyone was interested.

Joanne Kelleher
SecureRF Corporation
RFID Security Alliance Marketing Committee

Tuesday, October 27, 2009

Australia takes the application of electronic travel documents to the next level

Since their initial rollout, RFID-enabled electronic passports have seen wide-spread adoption in the US, Europe and other countries. It is also nothing new that biometric and other data can be read off the chip by unauthorized third parties and, in some cases, also be forged.

[http://www.timesonline.co.uk/tol/news/uk/crime/article4467098.ece]

But so far, the International Civil Aviation Organization (ICAO) has always insisted that despite any potential security concerns there would never be any fully automated immigration process and that the manual inspection by the immigration officer would serve as last line of defense that cannot be easily fooled.

Now the Australian government has introduced just that: After conducting a multi year trial the so called “SmartGate” system is being deployed at major Australian airports. SmartGate is a fully automated immigration procedure, involving having your passport scanned at a self-service terminal and then using an automatic immigration gate employing face recognition technology to match a live picture taken on the spot against the photo stored inside your passport.

[http://www.customs.gov.au/site/page.cfm?u=5831]

If you think about it, what’s happening in Australia is just the next logical step. After all the purpose of introducing electronic documents is, besides added security, to automate and streamline otherwise manual processes to save both time and money. But it also highlights once again the design flaws that had security experts around the world raise concerns ever since the introduction of the electronic passport.

At this point the SmartGate system is open to citizens of Australia and New Zealand aged 18 and over only, but over time the system is expected to open up to citizens of other nations as well.

Boris Wolf
VP of Business Development and Co-Founder
NeoCatena Networks, Inc.


Friday, October 2, 2009

Message from the incoming Chairperson

As the incoming chair of the RFID Security Alliance I want to thank all of those individuals who have contributed to the success of the Security Alliance. The Alliance represents perhaps the most knowledgeable group of individuals in the RFID community who have voluntarily come together to share ideas and start a long process of providing security improvements to our technical community and to the public at large.

Given ehealth mandates, the pharma-industries concerns over counterfeit drugs, and the food industries focus on tracking and tracing the perishable supply chain, RFID and RFID security issues will be more in the forefront of corporate thinking than before. The Alliance will be scheduling presentations and enlisting members to present topics that will be focused on industry wide issues during the fourth quarter 2009.

In addition we are starting a membership drive to ask for contributions to cover the legal costs to convert the organization to a non-profit status. This status will enable the organization to qualify for federal , state and local grants for RFID security issues and research. So if you can contribute send an email to our Secretary/Treasurer Anna Haight (mailto:a@qlmconsulting.com). In all cases your energy and expertise are greatly appreciated.



Michael McCartney
Chairperson
RFID Security Alliance

Tuesday, August 4, 2009

Feds at DefCon Alarmed After RFIDs Scanned | Threat Level | Wired.com

http://www.wired.com/threatlevel/2009/08/fed-rfid/


____________
D. Mike Ahmadi
P: (925) 413-4365
E: MikeAhmadi@mikeahmadi.com

Sent from my phone, so please forgive spelling and punctuation errors.

Friday, July 17, 2009

Reporters: Unsure of the RFID Security Facts? Contact the RFIDSA.

Contributed by Joanne C. Kelleher

Earlier this week one of my co-workers sent me a link with the comment “No surprise, but this kind of guy really irritate me.” The article, Chips in official IDs raise privacy fears by AP National Writer, Todd Lewan appeared in several places including http://news.yahoo.com/s/ap/20090711/ap_on_bi_ge/us_chipping_america_iv. It also triggered follow up articles such as Robin Harris’ blog post on ZDnet entitled RFID passports: a tragedy waiting to happen.

I was planning to post about how much of the content was old news or technically incorrect. For example, Harris mixed up Pass Cards and Passports which use different RFID protocols and have different security features. But Mark Roberti, editor of RFID Journal, beat me to it so I am going to refer you to his postings -AP Hack Strikes Again and Another Blogger Confuses the RFID Issue.

If any reporters wish to write about RFID security issues in the future, please contact the RFID Security Alliance and we can refer you to people who can accurately talk about the topic.

Tuesday, May 12, 2009

RFID Privacy and Data Protection Principles

Contributed by Joanne C. Kelleher

The Commission of The European Communities issued a recommendation today “on the implementation of privacy and data protection principles in applications supported by radio-frequency identification.”

Their “recommendation provides guidance to Member States on the design and operation of RFID applications in a lawful, ethical and socially and politically acceptable way, respecting the right to privacy and ensuring protection of personal data.”

Here is a summary of the recommendations:
  • Develops a framework for privacy and data protection impact assessments
  • Identify those applications that might raise information security threats then develop new schemes, or apply existing schemes, in order to demonstrate that an appropriate level of information security and protection of privacy is established in relation to the assessed risks.
  • Develop and publish a concise, accurate and easy to understand information policy for each RFID application and inform individuals of the presence of RFID readers for the application.
  • Inform individuals of the presence of RFID tags that are placed on or embedded in products in the retail trade, determine whether tags placed on or embedded in products sold to consumers through retailers by others represent a likely threat to privacy or the protection of personal data and deactivate or remove at the point of sale tags used in their application.
  • Take appropriate measures to inform and raise awareness among public authorities and companies of the potential benefits and risks associated with the use of RFID technology, especially information security and privacy aspects.
  • Stimulate and support the introduction of the ‘security and privacy by design’ principle at an early stage in the development of RFID applications.
These first two recommendations sound awfully familiar to those involved in the RFID Security Alliance. Performing risk assessments, which should cover both data protection and privacy issues, and then implementing the appropriate level of security and protection is a recommendation that we have been making since the RFIDSA’s formation. We also support designing privacy and security into the application at the beginning of the technology development process, not shoehorning it in at the end (like with DVDs).

I also found several of the Commission’s reasons behind these recommendations (the “whereas” clauses in the beginning of the document) to be right on target:

6.) Because of its potential to be both ubiquitous and practically invisible, particular attention to privacy and data protection issues is required in the deployment of RFID. Consequently, privacy and information security features should be built into RFID applications before their widespread use (principle of ‘security and privacy-bydesign’).

13.) RFID application operators should take all reasonable steps to ensure that data does not relate to an identified or identifiable natural person through any means likely to be used by either the RFID application operator or any other person, unless such data is processed in compliance with the applicable principles and legal rules on data protection.

19.) An assessment of the privacy and data protection impacts carried by the operator prior to the implementation of an RFID application will provide the information required for appropriate protective measures. Such measures will need to be monitored and reviewed throughout the lifetime of the RFID application.

22.) RFID applications with implications for the general public, such as electronic ticketing in public transport, require appropriate protective measures. RFID applications that affect individuals by processing, for example, biometric identification data or health related data, are especially critical with regard to information security and privacy and therefore require specific attention.

26.) Research and development on low-cost privacy-enhancing technologies and information security technologies is essential at Community level to promote a wider take-up of these technologies under acceptable conditions.

A full copy of the document, issued May 12, 2009, is at http://ec.europa.eu/information_society/policy/rfid/documents/recommendationonrfid2009.pdf. Also check out their RFID page at http://ec.europa.eu/information_society/policy/rfid/index_en.htm.