benjamin fabian, oliver g¨unther and sarah spiekermann humboldt-university berlin spandauer str. 1,...

17
Benjamin Fabian, Oliver G¨unther and Sarah Spiekermann Humboldt-University Berlin Spandauer Str. 1, 10178 Berlin, Germany 報報報 報報報

Upload: rachel-turner

Post on 13-Dec-2015

230 views

Category:

Documents


0 download

TRANSCRIPT

Benjamin Fabian, Oliver G¨unther and Sarah Spiekermann

Humboldt-University BerlinSpandauer Str. 1, 10178 Berlin, Germany

報告者:向峻霈

Outline1. The EPC Network2. DNS Threat 3. EPC Confidentiality and Privacy4. Mitigation Attempts5. Discussion

The EPC Network

Electronic Product Code(EPC)Tags and Reader EPC Middleware Object Name Service---(ONS)EPC Information Services---(EPC-IS)

The EPC Network

RFID Tag-to-Reader Communication

The EPC Network

ONS Resolution

The EPC Network

EPC-IS Access

DNS ThreatPacket interception(封包攔截 )Query prediction(預測查詢 )Cache poisoning(快取中毒 )Betrayal by trusted server(背叛信任伺服器 )

Denial of service(阻斷服務攻擊 )

EPC Confidentiality and Privacy

There are many contexts where the EPC of a RFID tag

could be regarded as highly sensitive information

the eavesdropper could easily add fake serial parts to the captured incomplete EPC and query the corresponding EPC-IS servers until a match is found

EPC Confidentiality and PrivacySSL/TLS 加密

The main privacy enhancing strategy lies in obfuscating the source IP or the real physical orign of the query

ONS ThreatONS context refers to the correctness and

completeness

if only due to its necessary widespread accessibility.ONS 將會成為一個在網路上高度暴露的被攻擊者

可能會被下列攻擊Distributed Denial-of-Service (DDoS)man-in-the-middle

Mitigation AttemptsNetwork DesignVirtual Private Networks and ExtranetsAnonymous MixesDNSSEC

Network Designinternal and private version of the EPC

network without depending on outside information優點: EPC封包不會洩漏 限制內部攻擊者 降低風險完整性缺點:無法在網路作動態更新等動作

prolonging of ONS and EPC-IS caching time

VPN and Extranets

Anonymous Mixes

Discussion什麼部分的 EPC和儲存信息應考慮公開,以及如何存取權限配置?

如果這些存取權限已經影響結果查找的服務?

謝謝大家的聆聽