Security Enhanced RFID Middleware System

Recently, the RFID (Radio Frequency Identification) technology attracts the world market attention as essential technology for ubiquitous environment. The RFID market has focused on transponders and reader development. But that concern has shifted to RFID software like as high-valued e-business applications, RFID middleware and related development tools. However, due to the high sensitivity of data and service transaction within the RFID network, security consideration must be addressed. In order to guarantee trusted e-business based on RFID technology, we propose a security enhanced RFID middleware system. Our proposal is compliant with EPCglobal ALE (Application Level Events), which is standard interface for middleware and its clients. We show how to provide strengthened security and trust by protecting transported data between middleware and its client, and stored data in middleware. Moreover, we achieve the identification and service access control against illegal service abuse. Our system enables secure RFID middleware service and trusted e-business service.




References:
[1] Whiting R., "RFID growth poses a data management challenge,"
Computing, 26 Feb. 2004, pp.29-30. Publisher: VNU Business
Publications, UK.
[2] Benetton Explains RFID Privacy Flap, RFID Journal, June 23, 2003,
http://www.rfidjournal.com/article/articleview/471/1/1/
[3] EPCglobal Web site. www.epcglobalinc.org, 2005.
[4] J. Collins. Marks & Spencer expands RFID retail trial. RFID Journal, 10
February 2004.
[5] Tesco Pushes on with Full-scale RFID Rollout.
http://www.computing.co.uk/news/1160636, January, 2005.
[6] S.A. Weis. Radio-frequency identification security and privacy. Master-s
thesis, M.I.T., June 2003.United States Food and Drug Administration.
Combatting counterfeit drugs: A report of the Food and Drug
Administration, 18 February 2004. Available at
http://www.fda.gov/oc/initiatives/counterfeit/report02 04.html.
[7] Filtering and Collection Threat Analysis. Technical report, EPCGlobal
Inc, July 2004.
[8] The Application Level Events (ALE) Specification, Version 1.0,
EPCGlobal Inc, September 2004.
[9] EPCglobal Object Name Service (ONS) 1.0. Technical report,
EPCGlobal Inc, April 2004.