TR 187 020 V1.1.1 (2011-05) Technical Report
Total Page:16
File Type:pdf, Size:1020Kb
ETSI TR 187 020 V1.1.1 (2011-05) Technical Report Radio Frequency Identification (RFID); Coordinated ESO response to Phase 1 of EU Mandate M436 2 ETSI TR 187 020 V1.1.1 (2011-05) Reference DTR/TISPAN-07044 Keywords privacy, RFID, security ETSI 650 Route des Lucioles F-06921 Sophia Antipolis Cedex - FRANCE Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16 Siret N° 348 623 562 00017 - NAF 742 C Association à but non lucratif enregistrée à la Sous-Préfecture de Grasse (06) N° 7803/88 Important notice Individual copies of the present document can be downloaded from: http://www.etsi.org The present document may be made available in more than one electronic version or in print. In any case of existing or perceived difference in contents between such versions, the reference version is the Portable Document Format (PDF). In case of dispute, the reference shall be the printing on ETSI printers of the PDF version kept on a specific network drive within ETSI Secretariat. Users of the present document should be aware that the document may be subject to revision or change of status. Information on the current status of this and other ETSI documents is available at http://portal.etsi.org/tb/status/status.asp If you find errors in the present document, please send your comment to one of the following services: http://portal.etsi.org/chaircor/ETSI_support.asp Copyright Notification No part may be reproduced except as authorized by written permission. The copyright and the foregoing restriction extend to reproduction in all media. © European Telecommunications Standards Institute 2011. All rights reserved. DECTTM, PLUGTESTSTM, UMTSTM, TIPHONTM, the TIPHON logo and the ETSI logo are Trade Marks of ETSI registered for the benefit of its Members. 3GPPTM is a Trade Mark of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. LTE™ is a Trade Mark of ETSI currently being registered for the benefit of its Members and of the 3GPP Organizational Partners. GSM® and the GSM logo are Trade Marks registered and owned by the GSM Association. ETSI 3 ETSI TR 187 020 V1.1.1 (2011-05) Contents Intellectual Property Rights ................................................................................................................................ 6 Foreword ............................................................................................................................................................. 6 1 Scope ........................................................................................................................................................ 7 2 References ................................................................................................................................................ 7 2.1 Normative references ......................................................................................................................................... 8 2.2 Informative references ........................................................................................................................................ 8 3 Definitions and abbreviations ................................................................................................................. 11 3.1 Definitions ........................................................................................................................................................ 11 3.2 Abbreviations ................................................................................................................................................... 13 4 Summary of findings and recommendations .......................................................................................... 13 4.1 Overview of findings ........................................................................................................................................ 13 4.2 Clarification of definition of RFID ................................................................................................................... 14 4.3 Summary of standardisation gaps ..................................................................................................................... 15 4.3.1 General principles ....................................................................................................................................... 15 4.3.2 Standards to provide greater consumer awareness ...................................................................................... 15 4.3.3 Standards in the privacy domain (excluding PIA) ...................................................................................... 15 4.3.4 PIA standards .............................................................................................................................................. 16 4.3.5 RFID Penetration testing standards ............................................................................................................ 16 4.3.6 Standards in the security domain ................................................................................................................ 16 4.4 Gaps in current standards ................................................................................................................................. 17 4.4.1 Overview .................................................................................................................................................... 17 4.4.1.1 Summary of main gaps .......................................................................................................................... 18 4.4.2 Gantt chart for addressing gaps in Phase 2 of M/436 ................................................................................. 18 5 Addressing consumer aspects ................................................................................................................. 21 5.1 Awareness ........................................................................................................................................................ 21 5.2 Personal data security ....................................................................................................................................... 21 5.3 Data Protection Requirements .......................................................................................................................... 22 5.3.1 Purpose ....................................................................................................................................................... 22 5.3.2 Deactivation ................................................................................................................................................ 22 5.3.3 Consent ....................................................................................................................................................... 22 5.3.4 Personal data record access and data correction ......................................................................................... 23 5.4 Accessibility of applications and consumer information .................................................................................. 23 6 The RFID ecosystem .............................................................................................................................. 23 6.1 Overview .......................................................................................................................................................... 23 6.2 Types of RFID Tags ......................................................................................................................................... 24 6.3 RFID Tag Characteristics ................................................................................................................................. 24 6.4 Stakeholders ..................................................................................................................................................... 25 6.5 Open and closed system applications ............................................................................................................... 25 6.6 RFID and IoT ................................................................................................................................................... 26 7 Analysis in support of recommendations ............................................................................................... 26 7.1 RFID system architecture ................................................................................................................................. 26 7.2 RFID system and privacy ................................................................................................................................. 27 7.2.1 Modelling the role of RFID in privacy ....................................................................................................... 28 7.3 Principles for handling personal data in RFID systems .................................................................................... 31 7.4 Role of Privacy Enhancing Technologies (PETs) ............................................................................................ 35 8 Data Protection, Privacy and Security Objectives and Requirements .................................................... 36 8.1 Distinguishing objectives and requirements ..................................................................................................... 36 8.2 Data protection and privacy objectives ...........................................................................................................