Title :
Privacy-enhanced filtering and collection middleware in EPCglobal networks
Author :
Tounsi, Wiem ; Cuppens-Boulahia, Nora ; Cuppens, Frederic ; Garcia-Alfaro, Joaquin
Author_Institution :
Inst. Mines-Telecom, TELECOM Bretagne, France
Abstract :
Collection and distribution of Radio Frequency IDentification (RFID) data are subject to various privacy concerns. These concerns are of paramount importance when sensitive data are processed (e.g., medical data). Therefore, it is crucial to treat sensitive data privacy in early stages to master the data view for upper layers and to minimize, as soon as possible, the risk of unauthorized disclosures. While most recent works focus on securing the access and visibility of collected information in the final databases, data processed in the middleware do not seem involved in the process of privacy protection. Current EPCglobal standards for RFID also suffer from insufficient attention to this issue. In this paper, we propose a privacy controller module that enhances the Filtering and Collection (F&C) middleware of the EPCglobal network. We provide a privacy policy-driven model, using some enhanced contextual concepts of the extended Role Based Access Control model. The feasibility of our privacy-enhanced model is shown by integrating our solution into the F&C middleware of the Fosstrak framework, an open-source implementation of the EPCglobal network specifications.
Keywords :
authorisation; data privacy; middleware; radiofrequency identification; EPCglobal networks; Fosstrak framework; RFID data; extended role based access control model; open-source implementation; privacy controller module; privacy policy-driven model; privacy protection; privacy-enhanced filtering and collection middleware; radio frequency identification data; sensitive data privacy; Data models; Filtering; Middleware; Object recognition; Protocols; Real-time systems; Security; EPCglobal; Fosstrak; Middleware; Privacy; RFID; Security;
Conference_Titel :
Risks and Security of Internet and Systems (CRiSIS), 2013 International Conference on
Conference_Location :
La Rochelle
DOI :
10.1109/CRiSIS.2013.6766358