• DocumentCode
    1071082
  • Title

    Credential Management for Automatic Identification Solutions in Supply Chain Management

  • Author

    Henseler, Marcel ; Rossberg, Michael ; Schaefer, Guenter

  • Author_Institution
    Telematics & Comput. Networks Group, Tech. Univ. Ilmenau, Ilmenau
  • Volume
    4
  • Issue
    4
  • fYear
    2008
  • Firstpage
    303
  • Lastpage
    314
  • Abstract
    Current systems for automatic identification of goods presume a single administrative domain. However, in supply chain management systems temporary cooperations of multiple companies exist, and the usage of one identification device, such as a radio-frequency identification (RFID) tag, per company is infeasible for reasons of costs, space requirements, traceability, and higher collision rate. This paper analyzes the security requirements resulting from the usage of a single tag for multiple companies and proposes a novel system architecture and accompanying cryptographic protocols that address the security objectives entity authentication, controlled access, data confidentiality and integrity, as well as untraceability of RFID tags. The architecture is designed to provide high availability and graceful degradation in case of compromise of system parts. The results of an implementation and simulation study give insights on appropriate data structures for realizing key functionality, and demonstrate the feasibility with off-the-shelf hardware.
  • Keywords
    cryptographic protocols; data integrity; message authentication; radiofrequency identification; supply chain management; RFID tag; automatic identification solutions; controlled access; credential management; cryptographic protocols; data confidentiality; data integrity; entity authentication; radio-frequency identification; security objectives; supply chain management; Authentication; Availability; Control systems; Costs; Cryptographic protocols; Data security; RFID tags; Radio frequency; Radiofrequency identification; Supply chain management; Access control; architecture; data security; identification; production management;
  • fLanguage
    English
  • Journal_Title
    Industrial Informatics, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1551-3203
  • Type

    jour

  • DOI
    10.1109/TII.2008.2009532
  • Filename
    4752848