<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>The RFID Ecosystem Blog</title>
	<atom:link href="http://rfid.cs.washington.edu/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://rfid.cs.washington.edu/blog</link>
	<description>A blog from a living laboratory for research in user-centered RFID systems</description>
	<pubDate>Wed, 09 Apr 2008 16:39:52 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
	<language>en</language>
			<item>
		<title>Talks from RFDM 08</title>
		<link>http://rfid.cs.washington.edu/blog/2008/04/07/talks-from-rfdm-08/</link>
		<comments>http://rfid.cs.washington.edu/blog/2008/04/07/talks-from-rfdm-08/#comments</comments>
		<pubDate>Mon, 07 Apr 2008 22:47:39 +0000</pubDate>
		<dc:creator>evan</dc:creator>
		
		<category><![CDATA[RFID Data Management]]></category>

		<category><![CDATA[RFID Security and Privacy]]></category>

		<category><![CDATA[Supply Chain]]></category>

		<category><![CDATA[Workshop]]></category>

		<category><![CDATA[Conference]]></category>

		<category><![CDATA[privacy]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://rfid.cs.washington.edu/blog/2008/04/07/talks-from-rfdm-08/</guid>
		<description><![CDATA[   Today&#8217;s talks covered a variety of topics, from effective and efficient strategies for managing RFID data in the supply chain, to a framework for security in interoperable RFID networks, to probabilistic RFID data cleaning and even RFID in mobile E-commerce.
One interesting talk on &#8220;Interoperable Internet Scale Security Framework for RFID Networks&#8221; was [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://rfid.cs.washington.edu/images/rfdm-afternoon.jpg" align="left" border="0" height="337" hspace="5" vspace="5" width="246" />   Today&#8217;s talks covered a variety of topics, from effective and efficient strategies for managing RFID data in the supply chain, to a framework for security in interoperable RFID networks, to probabilistic RFID data cleaning and even RFID in mobile E-commerce.</p>
<p>One interesting talk on &#8220;Interoperable Internet Scale Security Framework for RFID Networks&#8221; was given by Tingting Mao at the MIT AUTO-ID lab.  This work describes a framework whereby businesses can define policies for sharing EPC data and the associated business events.  A key feature of this system is that it uses authentication and authorization based on an aggregation of business rules, enterprise information, and RFID tag information. In another talk, Antti Sirkka from <a href="http://www.tietoenator.com/">TietoEnator</a> discussed &#8220;Modelling Traceability in the Forestry Wood Supply Chain&#8221;.  This work aims to use RFID to improve information on processes in the forestry wood production system - a pressing problem given the equivalent of Є5 billion of wood raw material going to waste in Europe.</p>
<p>There were also great talks and discussion from panelists <a href="http://www.cs.umass.edu/~yanlei/">Yanlei Diao</a> (<a href="http://www.cs.umass.edu/">University of Massachusetts, Amherst</a>) and <a href="http://magna.cs.ucla.edu/~wangfsh/">Fusheng Wang</a> (<a href="http://www.usa.siemens.com/en/research/">Siemens Corporate Research</a>).</p>
<p>Slides from the talks will eventually be posted online at: <a href="http://rfid.cs.washington.edu/rfdm08/">http://rfid.cs.washington.edu/rfdm08/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://rfid.cs.washington.edu/blog/2008/04/07/talks-from-rfdm-08/feed/</wfw:commentRss>
		</item>
		<item>
		<title>RFDM 2008 Workshop Today in Cancun, Mexico!</title>
		<link>http://rfid.cs.washington.edu/blog/2008/04/07/rfdm-2008-workshop-today-in-cancun-mexico/</link>
		<comments>http://rfid.cs.washington.edu/blog/2008/04/07/rfdm-2008-workshop-today-in-cancun-mexico/#comments</comments>
		<pubDate>Mon, 07 Apr 2008 16:34:42 +0000</pubDate>
		<dc:creator>evan</dc:creator>
		
		<category><![CDATA[RFID Data Management]]></category>

		<category><![CDATA[Supply Chain]]></category>

		<category><![CDATA[Workshop]]></category>

		<category><![CDATA[Conference]]></category>

		<guid isPermaLink="false">http://rfid.cs.washington.edu/blog/2008/04/07/rfdm-2008-workshop-today-in-cancun-mexico/</guid>
		<description><![CDATA[
   The first annual International Workshop on RFID Data Management (RFDM&#8217;08) is happening in Cancun today in conjunction with the International Conference on Data Engineering (ICDE).  The workshop brings together researchers and practitioners that work on problems related to managing data produced by RFID or other traceability and automated identification (Auto ID) [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center"><img src="http://rfid.cs.washington.edu/images/rfdm-title-blog.jpg" alt="RFDM 2008" border="0" height="175" hspace="5" vspace="5" width="624" /></p>
<p>   The first annual <a href="http://rfid.cs.washington.edu/rfdm08/">International Workshop on RFID Data Management (RFDM&#8217;08)</a> is happening in Cancun today in conjunction with the <a href="http://www.icde2008.org/">International Conference on Data Engineering (ICDE)</a>.  The workshop brings together researchers and practitioners that work on problems related to managing data produced by RFID or other traceability and automated identification (Auto ID) technologies. The goal is to fill an important gap in the community by bringing interested researchers together to identify future research challenges and opportunities.  The workshop is co-chaired by <a href="http://www.cs.washington.edu/homes/magda/">Prof. Magdalena Balazinska</a> and <a href="http://www.almaden.ibm.com/cs/people/murthy/">Dr. Karin Murthy</a> (<a href="http://www.almaden.ibm.com/cs/">IBM</a>).</p>
<p><a href="http://www-faculty.cs.uiuc.edu/~hanj/">Prof. Jiawei Han</a> (<a href="http://www.cs.uiuc.edu/">UIUC</a>) just gave a great keynote talk titled &#8220;Warehousing and Mining Massive RFID Data Sets&#8221;.  It covered some recent work he an his student <a href="http://daisy.cs.uiuc.edu/hector/index.html">Hector Gonzalez</a> have done on techniques for managing the massive (i.e. peta-byte scale) RFID data sets that are generated by supply chain applications of RFID.  He concluded with some <a href="http://daisy.cs.uiuc.edu/hector/vldb07_hagonzal.pdf">interesting work</a> that applies these techniques to the analysis and aggregation of traffic patterns using <a href="http://www.ezpass.com/">EZ-pass</a> and <a href="http://www.bayareafastrak.org/">FasTrak</a> data.</p>
]]></content:encoded>
			<wfw:commentRss>http://rfid.cs.washington.edu/blog/2008/04/07/rfdm-2008-workshop-today-in-cancun-mexico/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Karsten Nohl Speaks on RFID Security at UW Security Lunch</title>
		<link>http://rfid.cs.washington.edu/blog/2008/03/31/karsten-nohl-speaks-on-rfid-security-at-uw-security-lunch/</link>
		<comments>http://rfid.cs.washington.edu/blog/2008/03/31/karsten-nohl-speaks-on-rfid-security-at-uw-security-lunch/#comments</comments>
		<pubDate>Tue, 01 Apr 2008 07:38:45 +0000</pubDate>
		<dc:creator>evan</dc:creator>
		
		<category><![CDATA[RFID Security and Privacy]]></category>

		<category><![CDATA[privacy]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://rfid.cs.washington.edu/blog/2008/03/31/karsten-nohl-speaks-on-rfid-security-at-uw-security-lunch/</guid>
		<description><![CDATA[   Karsten Nohl spoke today at Prof. Yoshi Kohno&#8217;s weekly UW Security group lunch.  The topic of the talk was &#8220;The (Im)possibility of Hardware Obfuscation&#8221;.  In the talk, Karsten described the impracticality of hardware obfuscation techniques with a focus on the recent OV-chipkaart hack in which he played a key role. [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://rfid.cs.washington.edu/images/karsten-matching.jpg" align="right" border="0" height="299" hspace="5" vspace="5" width="259" />   <a href="http://www.cs.virginia.edu/~kn5f/">Karsten Nohl</a> spoke today at <a href="http://www.cs.washington.edu/homes/yoshi/">Prof. Yoshi Kohno&#8217;s</a> weekly <a href="http://www.cs.washington.edu/research/security.intro.html">UW Security</a> group lunch.  The topic of the talk was &#8220;The (Im)possibility of Hardware Obfuscation&#8221;.  In the talk, Karsten described the impracticality of hardware obfuscation techniques with a focus on the <a href="http://www.schneier.com/blog/archives/2008/01/dutch_rfid_tran.html">recent OV-chipkaart hack</a> in which he played a key role.  He also emphasized that it was quite feasible to reverse engineer Mifare Classic and similar hardware with a small budget and readily available tools (e.g. polishing paper, a microscope, Matlab).</p>
<p>Also in attendance were Starbug (Jan Krissler) from the <a href="https://berlin.ccc.de/wiki/Hauptseite">CCC in Berlin</a> and 3ric Johanson, a Seattle-area security professional, RFID hacker, and member of <a href="http://www.shmoo.com/">Shmoo</a>.  The presentation and discussion were great! A video of a similar talk which Karsten gave at Google can be found on his homepage: <a href="http://www.cs.virginia.edu/~kn5f/">http://www.cs.virginia.edu/~kn5f/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://rfid.cs.washington.edu/blog/2008/03/31/karsten-nohl-speaks-on-rfid-security-at-uw-security-lunch/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Expert Testimony From Prof. Balazinska on Privacy Risks of the EDL</title>
		<link>http://rfid.cs.washington.edu/blog/2008/01/30/expert-testimony-from-prof-balazinska-on-privacy-risks-of-the-edl/</link>
		<comments>http://rfid.cs.washington.edu/blog/2008/01/30/expert-testimony-from-prof-balazinska-on-privacy-risks-of-the-edl/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 07:36:12 +0000</pubDate>
		<dc:creator>evan</dc:creator>
		
		<category><![CDATA[RFID Security and Privacy]]></category>

		<category><![CDATA[RFID legislation]]></category>

		<category><![CDATA[EDL]]></category>

		<category><![CDATA[ORCA]]></category>

		<category><![CDATA[privacy]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[service]]></category>

		<category><![CDATA[WHTI]]></category>

		<guid isPermaLink="false">http://rfid.cs.washington.edu/blog/2008/02/12/expert-testimony-from-prof-balazinska-on-privacy-risks-of-the-edl/</guid>
		<description><![CDATA[Prof. Magdalena Balazinska testified at a public hearing today in the Washington State House Committee on Technology, Energy &#38; Communications. The hearing was on House Bill 2729, which addresses “the reading and handling of certain identification documents” and is sponsored by Rep. Deborah Eddy among others.  This is an especially timely bill in that [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://rfid.cs.washington.edu/images/olympia_sm.jpg" align="left" height="307" hspace="5" vspace="5" width="205" />Prof. Magdalena Balazinska testified at a public hearing today in the Washington State House Committee on Technology, Energy &amp; Communications. The hearing was on <a href="http://apps.leg.wa.gov/billinfo/summary.aspx?year=2008&amp;bill=2729">House Bill 2729</a>, which addresses “the reading and handling of certain identification documents” and is sponsored by <a href="http://www.housedemocrats.wa.gov/members/eddy/">Rep. Deborah Eddy</a> among others.  This is an especially timely bill in that it addresses privacy concerns raised by emerging public RFID systems such as the <a href="http://travel.state.gov/passport/ppt_card/ppt_card_3926.html">U.S. Passport Card</a>, the <a href="http://www.dol.wa.gov/driverslicense/edlfaq.html">Enhanced Driver’s License (EDL)</a>, and the new Puget Sound area transit pass, the <a href="http://www.orcatest.com/">ORCA card</a>.  The bill essentially limits the reading of RFID licenses and identicards as well as the use of the information contained on them. From the bill:</p>
<p>&#8220;[...] Washington state recognizes the importance of protecting the confidentiality and privacy of an individual&#8217;s personal information contained in drivers&#8217; licenses and identicards.&#8221;</p>
<p>&#8220;[...] A nongovernmental entity may only electronically read an individual&#8217;s driver&#8217;s license or identicard to verify the authenticity of the document or verify the individual&#8217;s age or identity. [...] When a nongovernmental entity electronically reads a driver&#8217;s license or identicard for one of the purposes permitted in (a) of this subsection, and except as otherwise permitted in subsection (3) of this section, the entity may not store, sell, or share personal information collected from the driver&#8217;s license or identicard without written consent of the individual.&#8221;</p>
<p>Magda provided expert testimony on the privacy risks of such systems.   Using examples from our research in the RFID Ecosystem project, Magda described how the lack of security features&#8230;<br />
(<a href="http://rfid.cs.washington.edu/blog/expert-testimony-from-prof-balazinska-on-privacy-risks-of-the-edl/">Read complete post &gt;&gt;</a>)</p>
]]></content:encoded>
			<wfw:commentRss>http://rfid.cs.washington.edu/blog/2008/01/30/expert-testimony-from-prof-balazinska-on-privacy-risks-of-the-edl/feed/</wfw:commentRss>
		</item>
		<item>
		<title>RFID Security: From Theory to Practice</title>
		<link>http://rfid.cs.washington.edu/blog/2008/01/27/rfid-security-from-theory-to-practice/</link>
		<comments>http://rfid.cs.washington.edu/blog/2008/01/27/rfid-security-from-theory-to-practice/#comments</comments>
		<pubDate>Mon, 28 Jan 2008 05:42:04 +0000</pubDate>
		<dc:creator>evan</dc:creator>
		
		<category><![CDATA[RFID Security and Privacy]]></category>

		<category><![CDATA[EDL]]></category>

		<category><![CDATA[privacy]]></category>

		<category><![CDATA[RFID]]></category>

		<category><![CDATA[RFID CUSP]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[talks]]></category>

		<category><![CDATA[WHTI]]></category>

		<category><![CDATA[workshops]]></category>

		<guid isPermaLink="false">http://rfid.cs.washington.edu/blog/2008/01/29/rfid-security-from-theory-to-practice/</guid>
		<description><![CDATA[ I was fortunate to participate in the RFID CUSP workshop at Johns Hopkins University last week.  The goal of the workshop was to bring together a broad cross-section of the RFID community in an effort to shape research agendas in service of pressing, real-world problems.
About half the speakers had government and/or industry backgrounds; [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.jhu.edu/~tour/images/wyman.jpg" alt="Johns Hopkins University" align="left" border="0" height="461" hspace="5" vspace="5" width="207" /> I was fortunate to participate in the <a href="http://www.rfid-cusp.org/">RFID CUSP</a> workshop at Johns Hopkins University last week.  The goal of the workshop was to bring together a broad cross-section of the RFID community in an effort to shape research agendas in service of pressing, real-world problems.</p>
<p>About half the speakers had government and/or industry backgrounds; the rest were RFID researchers.  Among the government speakers was <a href="http://www.dhs.gov/xabout/structure/bio_1166549785058.shtm">Hugo Teufel III</a>, the CPO of the U.S. Department of Homeland Security, who spoke about his office’s work on authoring <a href="http://www.dhs.gov/xinfoshare/publications/editorial_0511.shtm">Privacy Impact Assessments</a> for RFID-related issues such as WHTI and the EDL; he also said that he or someone from his office will go <em>anywhere</em> to speak on matters of privacy and homeland security (good to keep in mind!).  <a href="http://www.smartcardalliance.org/pages/alliance-management">Randy Vanderhoof</a> of the Smart Card Alliance also gave an interesting presentation on his organization’s work with privacy – this included a note on their <a href="http://www.smartcardalliance.org/pages/publications-whti-passport-card">strong opposition to the use of EPC Gen 2 technology for WHTI</a>.</p>
<p align="left">The research portion of the program included presentations from <a href="http://www.rsa.com/rsalabs/node.asp?id=2029">Ari Juels</a> and <a href="http://www.thingmagic.com/html/about/ravipappu.htm">Ravi Pappu</a> on practical key management techniques for crypto in real-world RFID applications.  <a href="http://www.crypto.ruhr-uni-bochum.de/en_paar.html">Christof Paar</a> reviewed some lightweight crypto techniques which his group had developed for RFID, while <a href="http://www.cs.vu.nl/~melanie/">Melanie Rieback</a> and <a href="http://www.cs.virginia.edu/~kn5f/index.html">Karsten Nohl</a>&#8230;<br />
(<a href="http://rfid.cs.washington.edu/blog/?page_id=4" title="RFID Security: From Theory to Practice">Read complete post &gt;&gt;</a>)</p>
<p align="left">&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://rfid.cs.washington.edu/blog/2008/01/27/rfid-security-from-theory-to-practice/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
