Showing posts with label RFID security. Show all posts
Showing posts with label RFID security. Show all posts

Tuesday, October 5, 2010

Privacy vs. Security on the DASH7 Wireless Sensor Networking Blog

The concepts of security and privacy are related, but different, and people often confuse the two issues. SecureRF’s CEO, Louis Parks, tackles this topic in his first posting for the DASH7 Wireless Sensor Networking Blog.

His post, Privacy vs. Security, lays down a foundation on what is security versus privacy, in a general, non-specific product way.
Future postings will cover:
  • “What is security?” and describe related tools and functions.
  • How you put these tools together to create security protocols that address real world issues.
  • Security on a DASH7 platform.
  • Addressing and describing the security needs and solutions for different applications and industries of interest to the DASH7 Alliance.
Pat Burns, President of the DASH7 Alliance, starts the conversation with his posting - Introducing Louis Parks.
The DASH7 Alliance was formed to advance the use of DASH7 wireless data technology by developing extensions to the ISO 18000-7 active RFID standard, ensuring interoperability among devices, and educating the market about DASH7 technology.  SecureRF is now a member of this organization.

Friday, April 30, 2010

Video: The Use of RFID in Supply Chain Security

Contributed by Joanne C. Kelleher

Last week was the annual INTERPHEX Conference for pharmaceutical manufacturers and packagers. Editors of BioPharm International and Pharmaceutical Technology conducted a series of in-depth conversations with speakers, industry stakeholders and thought leaders.

RFID Security Alliance members Louis Parks, CEO of SecureRF and Bikash Chatterjee, CTO of Pharmatech Associates, along with Anthony Palermo, Director of the RFID Centre of Excellence were interviewed together about the use of RFID in supply chain security.

You can view their interview at http://interphexvideocast.com/media/index.php?vid=Bikash_Anthony_Louis.

All of the interviews conducted at INTERPHEX are at http://interphexvideocast.com/

Friday, April 9, 2010

RFIDSA at RFID Journal LIVE 2010

RFID Journal LIVE 2010 is next week, April 14-16 in Orlando, FL.

Michael McCartney, RFID Security Alliance's chairperson, will be speaking in the RFID for IT Professionals track. His talk, titled RFID Security: Potential Threats, Their Impact and Solutions, will be presented on 4/14 at 11:30 am.

If you are going to this conference, please attend this session and introduce yourself to Michael.

Thursday, January 7, 2010

Karsten Nohl to Discuss Hacking Mifare and other 'secure' RFID on 1/13/2010

The RFID Security Alliance has changed the format of their monthly meetings and will now start with a discussion of a topic of interest. On January 13, 2010 researcher Karsten Nohl will mark the 25th anniversary month of declaring Mifare insecure by leading a discussion about Mifare and several other types of 'secure' RFID which have been broken in the meantime (HID, Legic).

Questions to be covered include:
  • How have the hacks on the Mifare transit cards impacted new projects?
  • How have existing systems been protected?
  • What is status of Mifare Plus?
  • How have other systems been broken?

Karsten bridges the three worlds of academic research, hacking, and industry. His academic research with the University of Virginia focuses on privacy protection in large networks. His hacking projects-- at H4RDW4RE in the Silicon Valley or with the CCC in Berlin--assess (and usually break) proprietary cryptography. Finally, his consulting job at McKinsey helps him understand why corporations often choose technically inferior solutions.
 
The meetings can be joined in person in California or via conference call. If you want to participate in next week's call (Wednesday, 1/13) on this topic, you are welcome to join us at 10 AM PST / 1PM EST. After this discussion and an open Q&A you can stay on the call for RFIDSA internal business topics if you wish.

Dial in Phone Number: 218.936.7999
Access code: 413685# (Follow the prompts)

RFID Security Alliance meetings are usually scheduled for the second Wednesday of each month at 10 AM PST / 1PM EST. More info about the RFID Security Alliance is at http://www.rfidsa.com/ or via the LinkedIn Group at http://www.linkedin.com/groups?gid=62849.


Contributed by Joanne C. Kelleher
RFIDSA Marketing Committee

Friday, July 17, 2009

Reporters: Unsure of the RFID Security Facts? Contact the RFIDSA.

Contributed by Joanne C. Kelleher

Earlier this week one of my co-workers sent me a link with the comment “No surprise, but this kind of guy really irritate me.” The article, Chips in official IDs raise privacy fears by AP National Writer, Todd Lewan appeared in several places including http://news.yahoo.com/s/ap/20090711/ap_on_bi_ge/us_chipping_america_iv. It also triggered follow up articles such as Robin Harris’ blog post on ZDnet entitled RFID passports: a tragedy waiting to happen.

I was planning to post about how much of the content was old news or technically incorrect. For example, Harris mixed up Pass Cards and Passports which use different RFID protocols and have different security features. But Mark Roberti, editor of RFID Journal, beat me to it so I am going to refer you to his postings -AP Hack Strikes Again and Another Blogger Confuses the RFID Issue.

If any reporters wish to write about RFID security issues in the future, please contact the RFID Security Alliance and we can refer you to people who can accurately talk about the topic.

Tuesday, May 12, 2009

RFID Privacy and Data Protection Principles

Contributed by Joanne C. Kelleher

The Commission of The European Communities issued a recommendation today “on the implementation of privacy and data protection principles in applications supported by radio-frequency identification.”

Their “recommendation provides guidance to Member States on the design and operation of RFID applications in a lawful, ethical and socially and politically acceptable way, respecting the right to privacy and ensuring protection of personal data.”

Here is a summary of the recommendations:
  • Develops a framework for privacy and data protection impact assessments
  • Identify those applications that might raise information security threats then develop new schemes, or apply existing schemes, in order to demonstrate that an appropriate level of information security and protection of privacy is established in relation to the assessed risks.
  • Develop and publish a concise, accurate and easy to understand information policy for each RFID application and inform individuals of the presence of RFID readers for the application.
  • Inform individuals of the presence of RFID tags that are placed on or embedded in products in the retail trade, determine whether tags placed on or embedded in products sold to consumers through retailers by others represent a likely threat to privacy or the protection of personal data and deactivate or remove at the point of sale tags used in their application.
  • Take appropriate measures to inform and raise awareness among public authorities and companies of the potential benefits and risks associated with the use of RFID technology, especially information security and privacy aspects.
  • Stimulate and support the introduction of the ‘security and privacy by design’ principle at an early stage in the development of RFID applications.
These first two recommendations sound awfully familiar to those involved in the RFID Security Alliance. Performing risk assessments, which should cover both data protection and privacy issues, and then implementing the appropriate level of security and protection is a recommendation that we have been making since the RFIDSA’s formation. We also support designing privacy and security into the application at the beginning of the technology development process, not shoehorning it in at the end (like with DVDs).

I also found several of the Commission’s reasons behind these recommendations (the “whereas” clauses in the beginning of the document) to be right on target:

6.) Because of its potential to be both ubiquitous and practically invisible, particular attention to privacy and data protection issues is required in the deployment of RFID. Consequently, privacy and information security features should be built into RFID applications before their widespread use (principle of ‘security and privacy-bydesign’).

13.) RFID application operators should take all reasonable steps to ensure that data does not relate to an identified or identifiable natural person through any means likely to be used by either the RFID application operator or any other person, unless such data is processed in compliance with the applicable principles and legal rules on data protection.

19.) An assessment of the privacy and data protection impacts carried by the operator prior to the implementation of an RFID application will provide the information required for appropriate protective measures. Such measures will need to be monitored and reviewed throughout the lifetime of the RFID application.

22.) RFID applications with implications for the general public, such as electronic ticketing in public transport, require appropriate protective measures. RFID applications that affect individuals by processing, for example, biometric identification data or health related data, are especially critical with regard to information security and privacy and therefore require specific attention.

26.) Research and development on low-cost privacy-enhancing technologies and information security technologies is essential at Community level to promote a wider take-up of these technologies under acceptable conditions.

A full copy of the document, issued May 12, 2009, is at http://ec.europa.eu/information_society/policy/rfid/documents/recommendationonrfid2009.pdf. Also check out their RFID page at http://ec.europa.eu/information_society/policy/rfid/index_en.htm.

Friday, April 3, 2009

Help Present a Balanced View of RFID Security

Bert Moore, Editor of AIM Global’s RFID Connections, discusses RFID security and privacy in his April 1, 2009 column titled RFID: Legislative Action.

"At some recent legislative hearings on whether to limit, regulate or restrict RFID in some way, advocates of RFID finally began to get their views heard. Why? Because many of the advocates weren't companies manufacturing or selling RFID, they were companies and agencies actively using the technology. They were able to point out to state legislators how the technology was actively benefitting citizens of the state. And their real world experiences helped put to rest some of the more outlandish claims of some privacy advocates.

At the same time, there are new concerns that some companies and governmental agencies are implementing RFID technology without giving adequate attention to the need for security and, therefore, privacy. Concerns about covert reading of ID cards and similar items must be addressed because they highlight real or potential system vulnerabilities that expose not only individuals but the entire system to unnecessary risk.

It is up to those in the RFID community -- both vendors and end users -- to be heard in legislative hearings and community forums in order to present a balanced view of the technology and point to ways in which it can be implemented securely so that it can continue to provide benefits while protecting the integrity of the system and personal privacy."

The RFID Security Alliance invites vendors and end users interested in this issue to join our organization.

Burt also goes on to announce the availability of a new technical report from the International Organization of Standards (ISO) which was based on the work of AIM Global. Publication ISO/IEC TR24729-4, Information technology - Radio frequency identification for item management - Implementation guidelines - Part 4: Tag data security is available for purchase from the AIM Global website.

I was pleased to see that this report “offers sufficient guidance to enable users or developers to assess potential risks and determine appropriate techniques to mitigate these risks.” The RFID Security Alliance encourages users and implementers to completing a risk assessment of potential RFID systems.

Thursday, February 19, 2009

RFID Security & Privacy and Search Engine Results

Contributed by Joanne C. Kelleher

Marketers know that you can track social trends by looking at search engine results for select phrases. As the director of Marketing at SecureRF Corporation, I have been tracking various key words related to radio frequency identification (RFID) for a couple of years and after seeing Mark Roberti’s latest RFID Journal blog entry I did a little more research.

Mark Roberti’s RFID Opponent Joins Ixquick.com blog entry discusses how the RFID Journal website appears as the top link in Ixquick.com with a rating of eight stars. Ixquick, a meta-search engine that uses other search engines to produce its results, dubs itself "the world's most privacy-friendly search engine." The more times a site appears at the top of search results such as Google, MSN and Yahoo, the higher a rating the site receives in Ixquick. Mark found RFID Journal’s high rating ironic because “Katherine Albrecht, founder of Consumers Against Supermarket Privacy Invasion and Numbering (CASPIAN) and an outspoken opponent of radio frequency identification—and, from time to time, of RFID Journal for its advocacy of the technology—has been placed in charge of public relations at Ixquick.com.”

In testing the phrase RFID Security (no quotes) in Ixquick I found that the blog I usually contribute to (the RFID Security blog) was ranked # 2 with six stars. The RFID Security Alliance homepage (RFIDSA.com) was ranked # 3 with six stars. Of the other “38 unique top-ten pages selected from at least 49,599,904 matching results” there were a mix of sites I expected, like Wikipedia and other RFID security vendors or organizations and a few disappointments, like a seven year old article and discount barcode vendor. Overall, these top results were focused on solutions to RFID security issues.

In comparison, the top result in Ixquick for the phrase RFID privacy was the Spychips site, a project of Katherine Albrecht’s CASPIAN organization. Most of the other “20 unique top-ten pages selected from at least 53,299,284 matching results” also focused on the issues and problems related to consumer privacy in the usage of RFID rather then solutions.

This trend of RFID security: solutions and RFID privacy: issues continued in Google. The phrase RFID Security currently results in about 1,060,000 Google results, a dramatic increase from about 518,000 to 626,000 pages at various times in 2008. I was pleasantly surprised to see that there are now 21 sponsored links for this phrase, including RFIDSA members Verayo and Neocatena. Until recently there were only a few paid listings for solutions to RFID security issues. In comparison, the phrase RFID currently results in over 21 million hits with 389 sponsored links and RFID privacy currently results in over 2 million hits but only 1 to 4 sponsored links (one of which was from Amazon for a book by the same name).

As the RFID Security Alliance was founded as a resource to drive market education and discussion about security and privacy issues surrounding the use of RFID technologies, solutions and applications, we can have a role in changing these trends. If your organization is interested in addressing these issues, regardless of where your website currently appears in the search engines, we invite you to join the RFIDSA - www.rfidsa.com.