Home > Security News > Low-cost way(s) to 'foil' low-tech RFID tags
Security News:
EMAIL THIS

Low-cost way(s) to 'foil' low-tech RFID tags

By Anne Saita, News Writer
12 Aug 2004 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

SAN DIEGO -- Though RFID devices come in all shapes and sizes, it's the tiniest tags using the technology that are bound to cause the biggest headaches, according to a presenter at Wednesday's USENIX Security Symposium.

Essentially small silicon chips attached to antennae and wrapped in paper or plastic, RFID tags, or "smart labels," can come with chips as small as a half millimeter. And though currently holding little virtual memory and limited computational power, retailers like Walmart and agencies like the Department of Defense are anxious to use the tags to track inventory. Part of the lure is the cost, currently about a nickel per tag.

But, warned Ari Juels, principal research scientist for Bedford, Mass.-based RSA Laboratories, "the very simple technology can give rise to a whole host of problems."

Declaring that "we're on the brink of an explosion in RFID use," Juels cautioned that the security community must find ways to quell privacy issues associated with potential uses of the tags, which can broadcast information to anyone with the right reader.

Some proposed solutions, such as carrying a protective mesh or aluminum foil to make detection difficult, aren't practical, he says, since tags can be placed in apparel from head to toe. An alternative is to "kill" the tags, essentially letting them self-destruct once they leave a store.

However, Juels said, "RFID tags are extremely beneficial devices and much too useful in their 'live' state." Killing them would undermine those benefits, such as to recover stolen goods or a lost pet, he explained.

A third option is enacting public policy, such as creating seals of approval that alert a consumer that the RFID tag conforms to a prescribed privacy policy. However, current tags can be read by anyone with a reader, so the guarantee means nothing.

Among the challenges for security circles to solve: the cheap tags' minimal cryptographic abilities make it hard to scramble information for privacy protection. Therefore, one avenue may be creating "rotating "pseudonyms to protect against the theft of tags' true unique identifier. But the limited storage of the tags also limits the number of pseudonyms, a setback if an attacker launches rapid-fire queries and can determine the real data. Therefore, researchers should look into creating query throttling to prevent such compromises.

Juels also discussed fledgling technology to block illegal tag reading by essentially spoofing all possible tag identifiers worldwide. This swamps a reader with data, essentially causing a denial of service.

"Polite blocking" lets a tag stop functioning in certain "privacy zones" and turn back on upon leaving. "Soft blocking" uses software to determine if a tag-holder has opted in or opted out of being identified, Juels said.

While current technology has plenty of wrinkles to iron out -- technical problems and growing privacy concerns chief among them -- RFID is not going away.

"Corporate privacy is not as colorful as consumer privacy," Juels said. "But it's just as important." Maybe more so, he added, since that's where RFID is being deployed at the moment.

Tags: Wireless Network Protocols and StandardsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Wireless Network Protocols and Standards
Wireless Security Lunchtime Learning
An introduction to wireless security
A wireless network vulnerability assessment checklist
Lesson 1: How to counter wireless threats and vulnerabilities
Lesson 1 quiz: Risky business
Wireless Security Lunchtime Learning Entrance Exam
Risky Business: Understanding WiFi threats
Study reveals lack of financial wireless computer security
Preparing enterprise Wi-Fi networks for PCI compliance
Cracks in WPA? How to continue protecting Wi-Fi networks

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts