Efficient Fine Grained Access Control for RFID Inter-Enterprise System

Authors

  • Bayu Anggorojati Center for TeleInFrastruktur (CTIF) Aalborg University, Denmark
  • Neeli Rashmi Prasad Center for TeleInFrastruktur (CTIF) Aalborg University, Denmark
  • Ramjee Prasad Center for TeleInFrastruktur (CTIF) Aalborg University, Denmark

DOI:

https://doi.org/10.13052/jcsm2245-1439.232

Keywords:

access control, policy, security, RFID, IoT

Abstract

Access control management is a very challenging task in an inter-enterprise RFID system due to huge amounts of information about things or objects that can be collected and accessed to and from the system. Furthermore, the information stored in the inter-enterprise RFID system contains sensitive and confidential data related to the activities of the organization involved around the RFID system. Hence, the efficiency and high-granularity are critical in the design of access control for such system. This paper presents a novel access control model which is efficient and fine grained for such a system. A detail definition and mechanism of the access control model are described in the paper. A system implementation is developed for the evaluation purpose. An important performance measure in big data processing is delay in processing time, thus the evaluation aims at measuring the access control processing time. The evaluation results show that the model is consistent, and is able to achieve less delay than the inter-enterprise RFID system without access control at a certain point.

Downloads

Download data is not yet available.

Author Biographies

Bayu Anggorojati, Center for TeleInFrastruktur (CTIF) Aalborg University, Denmark

Bayu Anggorojati received his B.E. degree in Electrical Engineering in 2005 from Institut Teknologi Bandung, Bandung, Indonesia. He received his MSc in Mobile Communication in 2007 from Aalborg University, Aalborg, Denmark. He joined Wireless Security and Sensor Network group within Network and Security Section (now CTIF Section) in the Electronic System of Aalborg University as a research assistant from 2007 till now. He has been involved in a number of EU-funded R&D projects, including FP7 CP Betaas for M2M & Cloud, FP7 CIP-PSP LIFE 2.0, FP7 IP ISISEMDICt for Demetia, and FP7 IP ASPIRE RFID and Middleware. He is currently pursuing his PhD degree at CTIF Section in Electronic System Department of Aalborg University, Denmark. His research interests include Radio Resource Management in OFDMA based system; Access Control, Authentication, and Key Management in the IoT/M2M and Cloud system.

Image

Neeli Rashmi Prasad, Center for TeleInFrastruktur (CTIF) Aalborg University, Denmark

Neeli Prasad is leading a global team of 20+ researchers across multiple technical areas and projects in Japan, India, throughout Europe and USA. She has a Master of Science degree from Delft University, Netherlands and a PhD degree in electrical and electronic engineering from University of Rome Tor Vergata, Italy. She has been involved in projects totaling more than $120 million – many of which she has been the principal investigator. Her notable accomplishments include enhancing the technology of multinational players including Cisco, HUAWEI, NIKSUN, Nokia-Siemens and NICT as well as defining the reference framework for Future Internet Assembly and being one of the early key contributors to Internet of Things. She is also an advisor to the European Commission and expert member of governmental working groups and cross-continental forums. Previously, she has served as chief architect on large-scale projects from both the network operator and vendor side looking across the entire product and solution portfolio covering wireless, mobility, security, Internet of Things, Machine-to-Machine, eHealth, smart cities and cloud technologies. She has more than 250 publications and published two of the first books on WLAN. She is an IEEE senior member and an IEEE Communications Society Distinguished Lecturer.

Ramjee Prasad, Center for TeleInFrastruktur (CTIF) Aalborg University, Denmark

Ramjee Prasad is currently the Director of the Center for TeleInfrastruktur (CTIF) at Aalborg University, Denmark and Professor, Wireless Information Multimedia Communication Chair. Ramjee Prasad is the Founding Chairman of the Global ICT Standardisation Forum for India (GISFI: www.gisfi.org) established in 2009. GISFI has the purpose of increasing of the collaboration between European, Indian, Japanese, North-American and other worldwide standardization activities in the area of Information and Communication Technology (ICT) and related application areas. He was the Founding Chairman of the HERMES Partnership – a network of leading independent European research centres established in 1997, of which he is now the Honorary Chair. He is the founding editor-in-chief of the Springer International Journal on Wireless Personal Communications. He is a member of the editorial board of other renowned international journals including those of River Publishers. Ramjee Prasad is a member of the Steering, Advisory, and Technical Program committees of many renowned annual international conferences including Wireless Personal Multimedia Communications Symposium (WPMC) and Wireless VITAE. He is a Fellow of the Institute of Electrical and Electronic Engineers (IEEE), USA, the Institution of Electronics and Telecommunications Engineers (IETE), India, the Institution of Engineering and Technology (IET), UK, and a member of the Netherlands Electronics and Radio Society (NERG), and the Danish Engineering Society (IDA). He is also a Knight (“Ridder”) of the Order of Dannebrog (2010), a distinguishment awarded by the Queen of Denmark.

References

Anggorojati, P. N. Mahalle, N. R. Prasad, and R. Prasad. Secure access control and authority delegation based on capability and context awareness for federated iot. In Fabrice Theoleyre and Ai-Chun Pang, editors, Internet of Things and M2M Communications. River Publisher, 2013.

ASPIRE. http://wiki.aspire.ow2.org.

L. Atzori, A. Iera, and G. Morabito. The internet of things: A survey. Computer Networks, 54(15):2787-2805, 2010.

E. Bertino, P. A. Bonatti, and E. Ferrari. Trbac: A temporal role-based access control model. ACM Trans. Inf. Syst. Secur., 4(3):191-233, August 2001.

R. Bhatti, E. Bertino, and A. Ghafoor. A trust-based context-aware access control model for web-services. In Web Services, 2004. Proceedings. IEEE International Conference on, pages 184-191, july 2004.

R. Bhatti, A. Ghafoor, E. Bertino, and J. B. D. Joshi. X-gtrbac: an xml-based policy specification framework and architecture for enterprise-wide access control. ACM Trans. Inf. Syst. Secur., 8(2): 187-227, May 2005.

EPCglobal. Epc information services (epcis) version 1.0.1 specification. September 2007.

EPCglobal. Gs1 epc tag data standard 1.6 – ratified standard. September 2011.

E. Grummt and M. Muller. Fine-grained access control for epc information services. In Proceedings of the 1st International Conference on The Internet of Things, IOT'08, pages 35-49, Berlin, Heidelberg, 2008. Springer-Verlag.

J. B. D. Joshi, E. Bertino, U. Latif, and A. Ghafoor. Ageneralized temporal role-based access control model. Knowledge and Data Engineering, IEEE Transactions on, 17(1):4-23, jan. 2005.

T. Karygiannis, B. Eydt, G. Barber, Lynn Bunn, and T. Phillips. Guidelines for securing radio frequency identification (rfid) systems – recommendations of the national institute of standards and technology. NIST Special Publication, April 2007.

R. S. Sandhu, E. J. Coyne, H. L. Feinstein, and C. E.Youman. Role-based access control models. Computer, 29(2):38-47, feb 1996.

XACML. https://www.oasis-open.org/standards#xacmlv2.0

Downloads

Published

2014-07-20

How to Cite

1.
Anggorojati B, Prasad NR, Prasad R. Efficient Fine Grained Access Control for RFID Inter-Enterprise System. JCSANDM [Internet]. 2014 Jul. 20 [cited 2024 Nov. 24];2(3-4):221-42. Available from: https://journals.riverpublishers.com/index.php/JCSANDM/article/view/6147

Issue

Section

Articles

Most read articles by the same author(s)