Construction oftheEnterprise-level RFIDSecurity andPrivacy Management UsingRole-Based KeyManagement
Chun-Te Chen, Kun-Lin Lee, Ying-Chieh Wu · 2006
The RFID technique isextensively applied in e-Business scope. Itmainly supports thequickly andaccurately workfortheadvanced assets management. Butitisstill lackof privacy protection ontheEPCcode. Fortheworsecase, some hackers maysteal thecodecontent easily during thecooperative business transmissions. Itwill causethebusiness secret leaking oreventheconsumerprivacy damage. Toencrypt theEPC code, wepropose atwophaseidentification andauthentication protocol withRBAC architecture toassure security. TheEPC codeisseparates randomly into twoparts bythesecret sharing method. OnlytheonehalfoftheEPCcodeisencrypted and stored intheRFIDtags. Theother partoftheEPCcodewas encrypted bytheprivate keyandstored atthebackend system forlater decrypted used. TheEPCcodeisdecrypted whenthese twoparts aredecrypted andmerged. Whentheownerofthetag ischanged, theencrypt EPC codeismergedthenseparated again. Inthis way,itisimpossible hasthesameencrypt EPC codeontheRFIDtagwhentheownerischanged. Thereader mustbeauthorized togetthesecret keybefore scanning and extracting thecorresponding product information. Hence, itcan ensure thatRFIDtagwill notreveal important information even though itisscanned byfakeornon-authorization reader. We alsoproposed a keymanagement basedonrole-base access controlmethodto distribute theaccesskeyand the encryption/decryption key, whichaligns wellwiththerole and thebusiness process ina supply chain. Thesecret keysare managedbytherole-based assignment attheenterprise level rather thanattheindividual level. Itnotonlyprovides with moreefficiency andflexibility ontherole's keymanagement, butalsoenhances thesecurity oftheenterprise-level RFID system. Therefore, thenumberofthesecret keytobemanaged isalsoreduced. Withtheproposed identification and authentication protocol, theRFIDcontent iscanencrypted efficiently toavoid theinformation eavesdropping ontheRFID system.