NIST Advises on RFID Security Risks

May 1, 2007

The National Institute of Standards and Technology describes some potential dangers of implementing RFID and offers guidelines and best practices for mitigating the risks.

Recognizing the potential risks inherent in the use of RFID technology, the National Institute of Standards and Technology, a nonregulatory agency of the U.S. Department of Commerce, has published its guidelines for deploying radio-frequency identification.

The Guidelines for Securing Radio Frequency Identification Systems, released April 27, are geared toward retailers, manufacturers, hospitals, federal agencies and other organizations that might utilize RFID along their supply chains. The 154-page document describes potential risks to data security and privacy that RIFD might engender. It also offers best practices and guidelines on how to mitigate some of those risks.

The NISTT Information Technology Laboratory is well suited to the task of handing down RFID best practices. The group develops tests, test methods, reference data, proof-of-concept implementations and technical analysis in order to "advance the development and productive use of IT," according to the guidelines.

The guidelines discuss the nature of RFID systems that companies might implement, the type of data that might be relayed from one system to another and the risks associated with implementing the technology. The paper lists four major risks companies face: business process risk; business intelligence risk, privacy risk and externality risk.

Business processes are at risk through potential "direct attacks" on RFID system components and could potentially undermine the processes the RFID system was designed to enable, according to the paper. The authors of the report - Tom Karygiannis, Bernard Eydt, Greg Barber, Lynn Bunn and Ted Phillips - give the example of a warehouse that relies solely on RFID to track items. An attack on system components could result in an inability to process orders.

A business intelligence risk could happen when an adversary or competitor gains unauthorized access to RFID-generated information and uses that information to "harm the interest of the organization," the report said.

"The example here is someone using an RFID reader to determine whether a shipping container holds expensive electronic equipment, and then targeting that container for theft. Privacy risks - particularly personal privacy rights - are at risk when someone uses what is considered personally identifiable information for a purpose other than it is intended or understood.

"As people possess more tagged items and networked RFID readers become ever more prevalent, organizations may have the ability to combine and correlate data across applications to infer personal identity and location, and build personal profiles in ways that increase the privacy risk," wrote the report's authors.

Finally, externality risk occurs when RFID technology presents a threat to non-RFID networked or co-located systems, assets and people. The report gives the example of an adversary gaining unauthorized access to computers on an enterprise network through IP-enabled RFID readers if the readers are not designed and configured properly.

To protect against these risks, NIST suggests that companies take the time to do some risk assessment, and then choose a mix of management, operational and technical security controls. There are many factors that need to be taken into account, including regulatory requirements, the magnitude of each threat and the cost of technology.

While the paper gives some specific guidelines and best practices, the overall message is that companies planning, implementing or managing an RFID system "should always consult the organization's privacy officer, legal council and CIO."

Copyright 2007 by Ziff Davis Media, Distributed by United Press International


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 4.7 /5 (3 votes)


May 1, 2007 all stories

Comments: 0

4.7 /5 (3 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • GTRI is developing protocols for testing effects of RFID systems on medical devices
    created Oct 06, 2009 | popularity not rated yet | comments 0
  • Chips in official IDs raise privacy fears
    created Jul 11, 2009 | popularity not rated yet | comments 0
  • Pilot study shows effectiveness of new, low-cost method for monitoring hand hygiene compliance
    created Mar 18, 2009 | popularity not rated yet | comments 0
  • Car key jams teen drivers' cell phones
    created Dec 11, 2008 | popularity not rated yet | comments 0
  • Study tackles labeling errors
    created Oct 06, 2008 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • CFP: ISNN2010 (June 6-10, 2010; Shanghai, China)
    created 8 hours ago
  • Secret Knock Detecting Lock
    created 17 hours ago
  • Gas engine running on Veggie oil - need help
    created 17 hours ago
  • Egg drop contest
    created 21 hours ago
  • More from Physics Forums - General Engineering

Other News

Google to buy mobile ad network for $750 million

Technology / Internet

created 54 minutes ago | popularity not rated yet | comments 0

(AP) -- Google Inc. is stepping up its push to sell advertising on cell phones, announcing a deal Monday to buy a mobile ad network, AdMob, for $750 million in stock.


Electronic Arts acquires Playfish for $275 million

Technology / Business

created 35 minutes ago | popularity not rated yet | comments 0

(AP) -- As its packaged video games business lags, Electronic Arts Inc. has snapped up Playfish Inc., the creator of popular social networking games such as "Who Has the Biggest Brain" and "Pet Society," for $275 million ...


Deadline arrives in Google book-scan deal (AP)

Deadline arrives in Google book-scan deal

Technology / Internet

created 51 minutes ago | popularity not rated yet | comments 0

(AP) -- The latest chapter is about to unfold in a four-year-old copyright lawsuit over Google's ambitious book-scanning project.


Tagged.com settles with NY, Texas in invite fight

Technology / Business

created 15 minutes ago | popularity not rated yet | comments 0

(AP) -- The social networking site Tagged.com has adopted reforms on the use of invitation e-mails after an attorney general alleged that the Web site essentially stole the identities of some 60 million Internet users.


Tesla Roadster

Tesla Roadster Goes 313 Miles on a Single Charge

Technology / Energy

created 2 hours ago | popularity 4.8 / 5 (4) | comments 1

(PhysOrg.com) -- Tesla is becoming synonymous with high performance electric cars. Indeed, the Tesla car company has been making efforts to create a brand of sports car that runs on electricity, and does so ...