首页> 外文会议>IEEE International Conference on Systems, Man and Cybernetics >Construction of the Enterprise-level RFID Security and Privacy Management Using Role-Based Key Management
【24h】

Construction of the Enterprise-level RFID Security and Privacy Management Using Role-Based Key Management

机译:使用基于角色的密钥管理构建企业级RFID安全和隐私管理

获取原文

摘要

The RFID technique is extensively applied in e-Business scope. It mainly supports the quickly and accurately work for the advanced assets management But it is still lack of privacy protection on the EPC code For the worse case, some hackers may steal the code content easily during the cooperative business transmissions. It will cause the business secret leaking or even the consumer privacy damage. To encrypt the EPC code, we propose a two phase identification and authentication protocol with RBAC architecture to assure security. The EPC code is separates randomly into two parts by the secret sharing method. Only the one half of the EPC code is encrypted and stored in the RFID tags. The other part of the EPC code was encrypted by the private key and stored at the backend system for later decrypted used. The EPC code is decrypted when these two parts are decrypted and merged. When the owner of the tag is changed, the encrypt EPC code is merged then separated again. In this way, it is impossible has the same encrypt EPC code on the RFID tag when the owner is changed. The reader must be authorized to get the secret key before scanning and extracting the corresponding product information. Hence, it can ensure that RFID tag will not reveal important information even though it is scanned by fake or non-authorization reader. We also proposed a key management based on role-base access control method to distribute the access key and the encryption/decryption key, which aligns well with the role and the business process in a supply chain. The secret keys are managed by the role-based assignment at the enterprise level rather than at the individual level. It not only provides with more efficiency and flexibility on the role's key management, but also enhances the security of the enterprise-level RFID system. Therefore, the number of the secret key to be managed is also reduced. With the proposed identification and authentication protocol, the RFID content is can encrypted efficiently to avoid the information eavesdropping on the RFID system.
机译:RFID技术广泛应用于电子商务范围。它主要支持快速准确地为先进的资产管理工作,但仍然缺乏对EPC代码的隐私保护,以便在更糟糕的情况下,一些黑客可以在合作业务传输期间轻松地窃取代码内容。它将导致业务秘密泄露甚至消费者隐私损失。要加密EPC代码,我们提出了一种具有RBAC架构的两相标识和认证协议,以确保安全性。 EPC代码通过秘密共享方法随机分为两部分。只有EPC代码的一半被加密并存储在RFID标签中。 EPC代码的另一部分由私钥加密,并存储在后端系统中,以便稍后解密使用。当这两个部分解密并合并时,EPC代码被解密。当标签的所有者更改时,将合并加密EPC代码然后再次分开。通过这种方式,当所有者改变时,不可能在RFID标签上具有相同的加密EPC代码。必须授权读者在扫描和提取相应的产品信息之前获取密钥。因此,它可以确保RFID标签不会透露重要信息,即使它被假或非授权读者扫描。我们还提出了基于角色的基本访问控制方法的密钥管理分布在供应链中的访问密钥和加密/解密密钥,其良好比对与角色和业务流程。秘密密钥由企业级别的基于角色的分配而不是个人级别管理。它不仅为角色的关键管理提供了更高的效率和灵活性,而且还提高了企业级RFID系统的安全性。因此,还减少了要管理的密钥的数量。利用所提出的识别和认证协议,RFID内容可以有效地加密,以避免在RFID系统上窃听信息。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号