Abstract:The recent RFID-based logistics environment enables significant improvement of business efficiency. However, to support an efficient logistics processing service in the RFID-based international logistics service platform, it is required security risk analysis and security control model. In this paper, we have analyzed and figured out requirements of the security for the efficient international RFID-based logistics service. It is possible to construct own security policy for each enterprise using RBAC. The security policy includes definition of subjects, objects, permissions, roles, role hierarchy and constraints of the enterprise. And we proposed an RBAC-based security control model, reflecting security requirements in an international logistics process and constraints of the access control model have been represented as UML. We presented example scenario and implemented the prototype system for the verification of the proposed security model for international logistics. The proposed security control model is useful to reduce business risk in international logistics.Keywords: RFID, International Logistics, RBAC, Security Control, Access Control Constraints.Framework) for each enterprise to construct its own security policy such as roles, permissions, sessions and constraints of the organization. Existing RFID-based international logistics platforms could become exposed to threats and security risks. Therefore we need flexible security control model for the protection of not only RFID threats but also enterprise level risks. RBAC is a powerful and flexible security access control model. So it can be applied to solve these problems.The rest of the paper is organized as follows. Section 2 describes the security guideline of the RFID system. We explain requirements of security in the EPC network application service based on RFID in section 3 and figure out security analysis in section 4. In section 5, we propose an RBAC-based security control model for the international logistics process and represent constraints of access control using UML. And section 6 contains example scenario and implementation of the proposed security model. Lastly a brief conclusion is presented in section 7.
Related WorksThe EPCglobal architecture framework is to be serviced for a mutual goal that intensifies the distribution/supply network by using EPC. EPCglobal network is a system that grants an identification number on a product based on RFID technology and EPC code, and conveys information related to the product for suppliers and consumers, by connecting a storage space of information into the network. In other words, EPCglobal network serves as a standard that makes it feasible to collect more than one EPC data from multiple-data resources, such as RFID reader, and report them in diverse form, by filtering and grouping them according to customized order from consumers, and to store data processed on the EPC IS (Information Services). EPCglobal network provides independence between application business logics and infrastructure...