Consumer Packaged Goods NEWS Text size: T T T

RFID Vendors Brief Congress on PASS Card Security

James Wiley, director of electronic documents at RFID chip, tag and reader maker Texas Instruments (TI), provided attendees an overview of the best practices his company recommends for the use of RFID in identity documents.

In any identity authentication system deployed by the government, Wiley explained, "there are two players: the citizen, whose identity is being challenged, and the government, who is working to authenticate the citizen. Both groups have serious and legitimate concerns, and any best practices need to address both groups." He added that "Security need not be attained at the price of privacy or operational efficiency," maintaining that clear rules must be set, pertaining both to the procedural and technological aspects of the identification system.

On the procedural side, Wiley stated, the government must inform each citizen, in advance, about which personally identifiable information is being collected, where this data is being collected, how it is being saved and with whom it is being shared. Citizens must also have a means of correcting inaccurate data linked to them through the identification system, and, whenever possible, their participation in the system should be voluntary.

On the technology side, he said, any RF-enabled identity document, and the reader used to collect data from that document, must each be authenticated by the government agency before any data is transmitted between the card and reader, to ensure both elements are legitimate and authorized. Moreover, all data transmitted via RF signals between a card and reader should be encrypted to protect it from being captured by an unauthorized party.

"RFID encompasses an incredibly wide range of technologies, and there are a lot of different flavors of this stuff," Wiley said, pointing in particular to the differences between the high-frequency cryptographically protected RFID inlays used in many identification and payment systems, and the long-range UHF inlays, incapable of supporting data encryption, that the DHS wants to use in the PASS card. TI manufactures both HF inlays that support data encryption and UHF inlays that do not.

For the benefit of the attendees, Wiley used a prototype PASS card containing an EPC Gen 2 UHF inlay and an off-the-shelf RFID interrogator to show how simple it is to capture and encode the prototype's identification number onto another EPC inlay. "The attendees were amazed by how quickly and easily the Gen 2 tags could be cloned," says Pattinson.

According to Pattinson, Gemalto and the other companies and groups at the briefing will continue to petition for the establishment of a technology trial in which EPC tags will be tested alongside high-frequency data-encrypted tags and other technologies.

READERS' COMMENTS

  • Security Issues with EPCglobal Gen 2

    Mary Catherine O'Connor - I was very interested in your July 20 article re "RFID Vendors Brief Congress on PASS Card Security" and the security concerns identified regarding EPCgobal Gen 2 technology for government sponsored security-orieinted applications. I share these concerns and am hoping you can provide additional information regarding your findings, or those of others, in this area. It would be very much appreciated if you could share any research you are aware of, or point me to such information sources. Many thanks for your assistance

    Posted By: S. Baumhardt 7/23/2007 at 12:43:24 PM

post a comment


Login and post your comment!

Forgot your password?


Not a member?
Signup for an account now to access all the features of RFIDJournal.com.




more Consumer Packaged Goods articles

PREMIUM CONTENT
TOOLS & RESOURCES
RFID Journal Map

sending it your way

Sign up for one of our E-Newsletters.

Enter Your Email Address:

take the poll

Are you concerned about your present or potential RFID technology provider going bankrupt?

RFID EVENTS

RFID Journal LIVE! 2012
Apr. 3-5, 2012
Orlando, Fla.

RFID Journal LIVE! Europe—Scandinavia
Oct. 24-25, 2012
Oslo, Norway

RFID BUYER’S GUIDE

Looking for RFID Products and Services?
Search the RFID Buyer’s guide to resources.

RFID Marketing Services
Cost-effective marketing now available.
rfidjournal.com/marketing
Get Pay-Per Click Ads on RFID Journal
More qualified leads than Google.
rfidjournal.com/textads