Monday, December 25, 2006
IBM's RFID tech to combat fake pharmaceuticals
Saturday, December 16, 2006
Your secrets not so safe with RFID-enabled passports
Ever since these newfangled RFID e-passports hit the mainstream, understandable concerns have frequently surfaced regarding the security (or lack thereof) involved. The Dutch version has already been cracked, Germans can clone theirs, and Ireland's doesn't even have a protective sheath to keep its data safe from unauthorized readers; now it appears that you have one more reason to stick with the ole laminated paper version, as security researchers have released "proof-of-contact code that they say enables an attacker to read the passport number, date of birth, and passport expiration date." The flaw was unveiled by Adam Laurie -- a well-respected watchman of Bluetooth security weaknesses -- in his "Bugtraq" newsletter, but no specifics were reported regarding how evildoers could extract such precious information and subsequently steal your identity. Nevertheless, those RFID-shielding manufacturers must be licking their chops right about now, and rightfully so.
Source:
Posted by Darren Murph in Engadget
Friday, December 15, 2006
Here comes RFID Gaurdian -Is it the Nemisis of RFID ?
Let's face. Researchers in Amsterdam have gone ahead and created a device which would prevent RFID tags from being read and this was being done with the aim of protecting users from this technology which was posing a threat to their privacy.
Called the RFID Guardian, it is a PDA size handheld device which warns a person that when a RFID scanner is trying to read a chip by beeping. This device runs on a 550MHz XScale 32 bit processor with 64Mbytes of RAM. The next few months would be spent by the research team on debugging and preparing the device for commercial use.
Though one can question its commerical viability as questioned by an industry observer who says that since RFID is touted to be next big thing in the pervasive computing, all materials in the future will come embedded with RF identification. RFID gaurdian would keep on warning, forcing the user to turn it off to stop the incessant beeping. Well, he goes to propose another model instead - A RFID Jammer.
This device, the size of a fountain pen, could act as a shield by emitting a constant RF jamming signal capable of preventing any RFID reader within a six foot radius from reading any of your RFID data. Now there is a device worth having.
Surely, the scientist from amsterdam is also listening. Expect some surprise too.
Thursday, December 14, 2006
RFID companies still not ready for growth, says expert
Frost & Sullivan recently reported that the total North American RFID market for manufacturing and logistics is predicted to grow at a compound annual growth rate of nearly 20 percent over the next six years. Yet, about 75 percent of the technology companies responding to a CompTIA survey earlier this year said there aren't enough people trained in the field. Eighty-percent said they believe that a lack of talent will hinder RFID adoption.
David Sommer, VP of e-business and software solutions at CompTIA, who speaks often about the looming shortage of RFID-trained workers, said that many factors are converging to promote RFID growth, but companies must focus on training workers to make sure the technology will work for them.
Global standards, interoperability, and declining prices are working in favor of rapid adoption, said Sommer, who worked with more than 20 organizations to develop CompTIA's professional RFID certification program. Sommer said he does not believe that there is a "magic number" for calculating when the cost of RFID technology will be low enough to trigger widespread adoption.
"We've seen where the tag itself, the semiconductor with the antenna, has gotten down to the 10- to 17-cent level," he said during a recent interview, adding that the prices vary depending on how companies deploy the technology. "The costs are continuing to decrease to the point where they are becoming very attractive."
In 2007, consumers will begin seeing more RFID tags on individual items. They will appear on higher-end electronics and pharmaceuticals before they make it into everyday products, he said.
"You're going to see them on expensive items, things that are easily counterfeited," he said. "It will be a ways down the road before you see it on the item level on something like toothpaste. It's a question of time and economics."
Eventually, when RFID is used in personal items such as clothing, retailers are likely to use technology that allows consumers to have the tags "killed" at checkout counters.
Item level RFID - the prosperous market 2006-2016
Item level RFID is the tagging of the smallest taggable unit of things - the library book, apparel, jewellery, engineering parts and laundry are examples. Already profitable for most suppliers, item level tags and systems will be the world's largest RFID market by value from 2007 onwards. Item level RFID tagging will rocket from $0.16 billion in 2006 to $13 billion in 2016 for systems including tags. In 2006, 0.2 billion items will be RFID tagged in the world. In 2016, 550 billion items may be RFID tagged. Those adopting item level tagging today do so willingly and are prepared to pay for good performance as they enjoy rapid multiple paybacks.
- Suitable for Electronic Product Code EPC coding/mass serialisation and open systems
- Small
- Made in millions to trillions yearly
- Need to read items individually but also many at a time
- Proximate metal and/or water
- Potential paybacks rarely worth more than a few percent of the value of the item tagged
- Tags need to be disposable or fitted for life
- Unquantifiable safety and security benefits are often sought and achieved
The US Food and Drug Administration will make tagging of up to 20 billion prescription drugs a legal requirement in the US, the TREAD Act will create a tire tagging market in the US and many new high priced retail items will enjoy the excellent paybacks currently found with apparel in the UK, China and Japan. China will rapidly adopt item level tagging. Globally, healthcare supplies, tools and assets are being urgently fitted with RFID for safety, security and cost control, including theft reduction. Boeing and Airbus are progressing the tagging of aircraft parts and equipment. Over ten million test samples for blood (Europe) and milk (New Zealand), drug research and other uses have been tagged with the potential of billions yearly.
However, it is challenging to meet the most sophisticated requirements for item level tagging and to evolve appropriate technical specifications and approval procedures for, say, mission critical aircraft parts. At the other extreme it is tough to get down to the price that justifies tagging a can of soda in a supermarket or a letter. Item level tagging has therefore started with the many lucrative intermediate requirements as shown below and it is rapidly widening in scope.

Source: IDTechEx

Source: IDTechEx

* May rise to 1000 in ten years as East Asia expands
Source: IDTechEx
Sunday, December 10, 2006
TI inks RFID smart label deal
Under the deal, TI becomes the primary supply of ultra-high frequency EP Gen 2 flexible inlays for new Moore Wallace RFID labels.
Specifically, TI's RF silicon components would be inserted into Moore Wallace's RFID thermal transfer labels, which customers can encode with RFID as well as print barcodes and text onto. The result is a label that is EPC Gen 2 ready.
Gen 2 is currently being reviewed by the International Standards Organization as the first global RFID technology standard. It is widely expected to get the green light from the ISO by early next year.
Under the deal, Moore Wallace would be able to make more than 500 million Gen 2 smart labels annually using TI silicon.
"[The deal] is unprecedented from the context of Gen 2 production readiness," said Enu Waktola, TI's EPC retail supply chain marketing manager.
Terms of the agreement were not disclosed.
This likely would be the first of many deals with RFID label markers for TI's Gen 2 inlays, said Erik Michielsen, director of RFID at ABI Research.
"This is significant in that it demonstrates how RFID solutions are ramping up for high-volume Gen 2 deployments," said Michielsen. "This is a big step for TI in that this is probably is the initial opening announcement for their Gen 2 label partners. I imagine there'll be more to come."
Waktola said the agreement with Moore Wallace was not exclusive and that TI also is working with other label makers.
It makes sense that TI struck its first Gen 2 label-making deal with Moore Wallace, one of the world's biggest makers of RFID labels, since the companies have been working together on RFID since 1998. "We are leveraging the relationship and production capabilities that we can bring together to the market," Waktola said.
While smaller silicon makers, notably Impinj, are also marketing Gen 2 inlays, Michielsen said partnerships between large companies such as TI and Moore Wallace give the RFID industry Gen 2 supply stability and clout. "It sheds a positive light on the future for Gen 2," he said.
The TI-Moore Wallace deal also points to where Gen 2 RFID product volumes are headed next year, Michielsen said.
Moore Wallace sells its RFID labels to between 30% and 40% of so-called compliance program suppliers in the US today, said Nancy Mitchell, Moore Wallace's RFID product manager. That is, companies who comply with the RFID mandates of large goods purchasers such as Wal-Mart, Target and the US Department of Defense.
Most of Moore Wallace's RFID customers are consumer goods product makers, Mitchell said. Industrial manufacturers, which include the DoD, are its next-largest group of customers, followed by pharmaceutical makers. While drug makers are fast adopting RFID, she expects this customer mix to remain unchanged for the next year or so.
TI's Waktola said she expects Gen 2 RFID hardware, such as readers and printers, to be on the market this quarter.
The new Moore Wallace smart labels are currently being sampled, with full production slated for later in the third quarter.
Mitchell said a number of consumer goods makers have already begun pilots of the labels and she expects them to convert to Gen 2 during the next two quarters.
Moore Wallace has distribution channels for the new labels in Asia, Europe and North and South America, she said.
Currently, the company would just manufacture the Gen 2 labels in North America and expects production at its plants in Asia, Europe and South America at some future point. "We've been discussing that internally but don't have any specific timelines," Mitchell said.
Saturday, December 9, 2006
RFID virus created
In a paper entitled "Is your cat infected with a computer virus?" presented before the IEEE International Conference on Pervasive Computing, three Netherlands-based researchers show how RFID tags can carry malware and propagate via databases along the supply chain.
"The security breaches that RFID deployers dread most - RFID malware, RFID worms, and RFID viruses - are right around the corner," wrote the study's principle researcher, Melanie Rieback, an American PhD student at Vrije university in Amsterdam.
The sky is not falling, of course, and the paper's main message seems to be that RFID software should not implicitly trust the data it pulls off RFID tags. It should be subject to the same security check as any potentially untrustworthy user input.
The paper's title refers to a hypothetical scenario outlined in the paper's introduction, in which a household pet implanted with an infected RFID tag is able to spread an infection to a veterinarian's computer system, with damaging consequences.
Rieback, and fellow researchers Bruno Crispo and Andrew Tanenbaum, found they were able to execute an SQL injection attack against an Oracle database and Apache web server using 127 characters of data stored on a cheap RFID tag.
SQL injection attacks are well-known from the web applications world. Using escape characters and SQL queries, crackers are sometimes able to interface directly with a back-end database, amending or deleting data as they see fit.
In Rieback's scenario, the virus uses SQL injection to write itself to a database whenever the infected tag is scanned. In a real-world scenario, this scan could happen when a pallet of goods arrives at a store or warehouse. New tags entering the system would have the viral code written to them.
"The manipulation of less than 1 Kbits of on-tag RFID data can exploit security holes in RFID middleware, subverting its security, and perhaps even compromising the entire computer, or the entire network," she wrote.
Rieback's paper outline a few other types of attack that could work from RFID tags. Even though RFID tags are limited in the amount of data they can store, she found that buffer overflow attacks are even possible, due to looping commands permitted by the RFID spec.
The research could open intriguing new possibilities in the field of virus propagation research.
Old floppy disk viruses spread along social networks, as friends and colleagues physically swapped disks and used them on their own computers. In a similar way, mobile phone viruses that spread via Bluetooth also require physical proximity to spread, much like their biological counterparts.
Email worms also spread along social lines, but over greater distances, using their victim's address books to find targets. Network worms have tended to have simple algorithms for randomly generating IP addresses to attempt to spread to.
There are not believed to be any recorded cases of malware designed to spread along the supply chain, but the new research seems to indicate that is at least a possibility.

