RFID tag data security technical report based on guidance from AIM's RFID expert group is published by ISO.
Trade association AIM Global, an authority on automatic identification and mobility has a new offering on their website: ISO/IEC TR24729-4, Information technology — Radio frequency identification for item management — Implementation guidelines — Part 4: Tag data security by the International Organization of Standards (ISO).
The Technical Report has its genesis as guidance from AIM Global's RFID Expert Group: RFID — Guidelines on data access security. It looks at systemic solutions that prevent unauthorized or inadvertent access to data on an RFID tag and in an RFID system. It is intended to provide guidance to users and systems designers on potential threats to data security and countermeasures available to provide RFID data security.
Determining the appropriate approach to RFID data security is highly dependent on the type(s) of possible threat(s), the intended use of the tag, the type of data on the tag for a particular application, and the potential value of the data. Therefore, this Technical Report does not provide specific recommendations but, rather, offers sufficient guidance to enable users or developers to assess potential risks and determine appropriate techniques to mitigate the risks they may see in their own application.
Key contributors to the development of the document include Dr. Gisele Bennet, Georgia Tech Research Institute (project chair); Matthew J. and Craig K. Harmon, QED Systems; Steve Halliday, HighTech AID; Mark Buckner, Oak Ridge National Labs; Eldor Walk, FEIG Electronic GmbH; Dan Kimball, SRA International; Mark Reboulet, U.S. Air Force AIT; and Bert Moore, AIM Global.
AIM Global president, Dan Mullen noted, "As with every data collection system, the security of information is an essential element to the solution. With increasing adoption of RFID, it is important for companies producing, implementing and using RFID to understand potential risks and rewards offered by the technology. This technical report is a tremendous resource to help companies understand and mitigate risks to maximize rewards."
All relevant automatic identification and data collection ISO documents are available for purchase from the AIM Global online store at:
https://www.aimglobal.org/estore/ProductDetails.aspx?productID=670