CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer
image RSA Seeks to Fix RFID Worries image
Privacy
August 25, 2003
RSA Seeks to Fix RFID Worries
By Dennis Fisher

Researchers at RSA Security Inc.'s lab have come up with a technique they said will eliminate many of the privacy concerns surrounding the use of RFID tags and enable enterprises and consumers to use the technology without worry.

The solution, which involves fooling RFID (radio frequency identification) readers into believing all possible tags are present at any given time, is an inexpensive, elegant answer to a number of the privacy and security questions being asked about RFID technology, security experts say.

RFID tags are being used in a quickly expanding array of industrial and corporate applications, most notably inventory control and tracking and security and access control.

The tags are tiny integrated circuits coupled with antennas. Each tag is programmed with a unique identification number, which it sends to a reader on request. The tags can be embedded in just about anything, including clothing, consumer goods, money and credit cards. Tags will be embedded in large euro notes within two years.

Privacy issues have surfaced because any reader can read the numbers on any tag. This means a reader in a department store, for example, could not only see what items a shopper has in her cart but could also see what other items she has purchased at competing stores, as well as how much money is in her wallet and what credit cards she's carrying.

The technology that RSA Labs is proposing would make it simple for corporations and consumers to decide which tags could be read by which readers and when. The solution uses what's known as a blocker tag to simulate all possible tag serial numbers. In doing so, it prevents the reader from discovering whether a specific tag is present.

The conceptual basis is reasonably simple, and the blocker tags should cost no more than twice what normal tags cost, said Ari Juels, principal research scientist at RSA Labs, in Bedford, Mass., and co-author of a paper on blocker tags. RFID tags typically cost about 5 cents each.

For details on enterprise RFID's ups and downs, check out CIO Insight's coverage.

RFID readers can't talk to more than one tag at a time, so when multiple tags reply to a query, the readers detect a collision and revert to what's known as a singulation protocol to communicate with each tag individually. To accomplish this, the reader queries each tag for its next bit, which identifies which portion of a binary tree the tag resides on. When queried, a blocker tag responds with a '0' and a '1' bit. This causes the reader to start over and explore the entire tree.

Such a tag could be programmed to block only a certain range of RFID serial numbers. This would still allow for benign uses of RFID tags while enabling users or corporations to control which tags are readable.

This is a brilliant idea. I'd like to see one of these blocking tags attached to my wallet or car keys so that all RFIDs would be blocked, said Avi Rubin, associate professor and technical director of the Information Security Institute at Johns Hopkins University, in Baltimore. Rubin has been researching some of the privacy implications of RFID tags. This is increasingly important as the tags get embedded in clothing and other personal items, he said.

RSA is in discussions with RFID manufacturers about developing the blocker tags.

We're going to need a range of solutions here, Juels said. He and his co-authors, Ron Rivest, one of the founders of RSA, and Michael Szydlo, also of RSA Labs, plan to present their paper on the blocker tags at the Association for Computing Machinery's Conference on Computer and Communications Security in October.



eWeek


Copyright (c) 2003 Ziff Davis Media Inc. All Rights Reserved.
Posted on Tuesday, 26 August 2003 @ 05:20:00 UTC by phoenix22 (965 reads)
[ Trackback ]
image

"RSA Seeks to Fix RFID Worries" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· HotScripts
· W3 Consortium
· More about Privacy
· News by phoenix22


Most read story about Privacy:
Ad-aware 6 Release from Lavasoft

block bottom
Article Rating
spacer
Average Score: 2
Votes: 1


Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer