Access and privacy control enforcement in RFID middleware systems: Proposal and implementation on the fosstrak platform

被引:0
|
作者
Wiem Tounsi
Nora Cuppens-Boulahia
Frédéric Cuppens
Guy Pujolle
机构
[1] Telecom Bretagne,
[2] LIP6/UPMC - University of Paris 6,undefined
来源
World Wide Web | 2016年 / 19卷
关键词
RFID; Access control; Privacy policy; Middleware; EPCglobal; Provisional context;
D O I
暂无
中图分类号
学科分类号
摘要
Radio Frequency IDentification (RFID) technology offers a new way of automating the identification and storing of information in RFID tags. The emerging opportunities for the use of RFID technology in human centric applications like monitoring and indoor guidance systems indicate how important this topic is in term of privacy. Holding privacy issues from the early stages of RFID data collection helps to master the data view before translating it into business events and storing it in databases. An RFID middleware is the entity that sits between tag readers and database applications. It is in charge of collecting, filtering and aggregating the requested events from heterogeneous RFID environments. Thus, the system, at this point, is likely to suffer from parameter manipulation and eavesdropping, raising privacy concerns. In this paper, we propose an access and privacy controller module that adds a security level to the RFID middleware standardized by the EPCglobal consortium. We provide a privacy policy-driven model using some enhanced contextual concepts of the extended Role Based Access Control model, namely the purpose, the accuracy and the consent principles. We also use the provisional context to model security rules whose activation depends on the history of previously performed actions. To show the feasibility of our privacy enforcement model, we first provide a proof-of-concept prototype integrated into the middleware of the Fosstrak platform, then evaluate the performance of the integrated module in terms of execution time.
引用
收藏
页码:41 / 68
页数:27
相关论文
共 50 条
  • [41] Security and Privacy Frameworks for Access Control Big Data Systems
    Centonze, Paolina
    CMC-COMPUTERS MATERIALS & CONTINUA, 2019, 59 (02): : 361 - 374
  • [42] A Semantic Access Control for easy management of the privacy for EHR Systems
    Sicuranza, Mario
    Ciampi, Mario
    2014 NINTH INTERNATIONAL CONFERENCE ON P2P, PARALLEL, GRID, CLOUD AND INTERNET COMPUTING (3PGCIC), 2014, : 400 - 405
  • [43] RF-Access: Barrier-Free Access Control Systems with UHF RFID
    Wang, Xuan
    Wang, Xia
    Yan, Yingli
    Liu, Jia
    Zhao, Zhihong
    APPLIED SCIENCES-BASEL, 2022, 12 (22):
  • [44] An Implementation of Efficient Hierarchical Access Control Method for VR/AR Platform
    Hsiao, Tsung-Chih
    Tai, Kuang-Yen
    Huang, Yu-Min
    Chung, Yu-Fang
    Wu, Yu-Chieh
    Kurniati, Tias
    Chen, Tzer-Shyong
    2018 16TH INTERNATIONAL CONFERENCE ON EMERGING ELEARNING TECHNOLOGIES AND APPLICATIONS (ICETA), 2018, : 205 - 208
  • [45] Authentication and Access Control in RFID Based Logistics-customs Clearance Service Platform
    Hui-Fang Deng1 Wen Deng2 Han Li3
    International Journal of Automation & Computing, 2010, 7 (02) : 180 - 189
  • [46] Authentication and access control in RFID based logistics-customs clearance service platform
    Deng H.-F.
    Deng W.
    Li H.
    Yang H.-J.
    International Journal of Automation and Computing, 2010, 7 (2) : 180 - 189
  • [47] Privacy Enforcement Strategies in Discrete Event Systems via Observation Modification and Supervisory Control
    Duan, Wei
    Hadjicostis, Christoforos N.
    Li, Zhiwu
    2021 EUROPEAN CONTROL CONFERENCE (ECC), 2021, : 68 - 73
  • [48] An Attribute-Based Access Control using chaincode in RFID systems
    Figueroa, Santiago
    Anorga, Javier
    Arrizabalaga, Saioa
    Irigoyen, Inigo
    Monterde, Mario
    2019 10TH IFIP INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES, MOBILITY AND SECURITY (NTMS), 2019,
  • [49] A Distributed Binary Tree Protocol for Medium Access Control in RFID Systems
    Baldi, Marco
    Morichetti, Stefano
    Gambi, Ennio
    2008 INTERNATIONAL CONFERENCE ON SOFTWARE, TELECOMMUNICATIONS AND COMPUTER NETWORKS, 2008, : 226 - 230
  • [50] Trust-Based Access Control in Storage Middleware Grids: A Reference Framework Proposal to Deploy in the Financial Sector
    Nunes, Francisco
    O'Neill, Henrique
    TECHNOLOGICAL INNOVATION FOR CLOUD-BASED ENGINEERING SYSTEMS, 2015, 450 : 54 - 61