<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>I Told You So, Volume 1 - rfid-security</title>
    <subtitle>Archive, Volume 1: conference talks and papers on security and risk, 2010 to 2018.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://blog.itys.net/vol1/tags/rfid-security/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2010-04-01T00:00:00+00:00</updated>
    <id>https://blog.itys.net/vol1/tags/rfid-security/atom.xml</id>
    <entry xml:lang="en">
        <title>ISO Focus+ Article: Plugging Security Gaps</title>
        <published>2010-04-01T00:00:00+00:00</published>
        <updated>2010-04-01T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/iso-focus-plus/"/>
        <id>https://blog.itys.net/vol1/posts/iso-focus-plus/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/iso-focus-plus/">&lt;p&gt;The attached article examines the explosive adoption of radio-frequency
identification (RFID) technology across industries and the emerging security
concerns that threaten its continued growth. As organizationsfrom the U.S.
Department of Defense to livestock ranchers and healthcare providersincreasingly
rely on RFID for tracking assets, the industry must confront vulnerabilities
that could undermine both privacy and trust in this pervasive technology.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;attacks&quot;&gt;Attacks&lt;&#x2F;h2&gt;
&lt;p&gt;In the face of demonstrated attackssuch as drive-by cloning of passport tagsRFID
systems are exposed to a spectrum of threats at multiple points: the tag itself,
the reader (interrogator), and the air interface. Common attack vectors include
mimicking (spoofing, cloning, malicious code), information gathering (skimming,
eavesdropping, data tampering), and denial-of-service tactics (reader jamming,
tag blocking or killing). Each of these can compromise confidentiality,
integrity, or availability, potentially disrupting business operations and
eroding user confidence.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;defense&quot;&gt;Defense&lt;&#x2F;h3&gt;
&lt;p&gt;To address these challenges, international standards bodies have moved to embed
security into RFID deployments. ISO&#x2F;IEC TR 24729-4 lays out guidelines for tag
data securitycovering encryption, authentication, and secure data
transmissionwhile balancing cost, storage constraints, and read-performance
requirements. The report recommends leveraging a suite of countermeasures (e.g.,
unique tag identifiers per ISO 15963, password protection, and cryptographic
controls) and employs the OWASP DREAD model to assess and prioritize risks.
Ongoing work by ISO&#x2F;IEC SC 31s WG 7 seeks to harmonize these efforts into a
coherent framework that ensures interoperability, efficiency, and privacy as
RFID becomes ever more ubiquitous.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;55287_2010-04-01_Plugging_Security_Gaps-ISOFP.pdf&quot;&gt;ISO Focus+ April
2010&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
