透過RFID的無線射頻感應技術,管理者能使用讀取器讀取標籤中的產品電子編碼以識別產品,因此RFID將成為未來供應鏈管理的一項利器。為提升自動化與商業透明度,供應商的後端伺服器紀錄產品每一登錄事件,以完成產品生產過程紀錄並提供線上查詢服務,大幅增進對產品流向與庫存供需的掌控度,因此RFID被視為下一代的條碼應用,但卻令有心人士欲利用RFID的安全弱點謀取市場情報、竊取隱私。有心人士能在有限範圍內使用惡意讀取器讀取標籤,或是竊聽合法讀取器與標籤之間的交換訊息,企圖識別標籤所紀錄之產品資訊、標籤位置、價格等有利資訊。因此需探討造成RFID系統安全威脅的攻擊所帶來的影響,例如竊聽、重送攻擊、偽冒標籤及非同步攻擊等。 為了有效防堵有心人士侵害他人利益之行為,本論文中提出兩個協定以確保RFID系統於供應鏈安全的可靠度並能妥善執行所有權轉移,且符合供應鏈環境與需求,能夠在可行性前提下達到安全性。第一個協定適用於生產至零售階段,利用兩個安全狀態等級以解決供應鏈上安全與效率互有抵觸的問題。第二個協定適用於商品出售後的消費者端,提出可執行離線讀取與離線所有權轉移的協定,能保障消費者所購買物品的所有權及個人隱私不受侵害。
Through the technique of radio frequency induction, managers can use the RFID reader to read the electronic product code label to identify products; hence the RFID will become a tool for supply chain management. In order to enhance automation and business transparency, the back-end server of the supplier records each log event to complete the production records and provide online inquiry service. RFID enabled the degree of control over the product flow and inventory, so RFID is seen as the next generation of bar code applications. And due to the drawback about the security of RFID, attackers can seek market intelligence or privacy. Attackers can use the malicious reader to read tags in a limited range, or eavesdrop on a successful communication between the tag and a legitimate reader. With this manner, product information can be collected and tracked. This study focus on security threats on RFID systems caused by eavesdropping, replay attacks, tag cloning, De-synchronization, etc. In order to protect commercial benefits from attackers, this study presented two RFID communication protocols to ensure that RFID systems can properly execute the transfer of ownership in RFID enabled supply chain environments that can keep the security. The first protocol applies to the production to the retail stage, use of two security levels to deal with the security and efficiency problems in the supply chain. The second protocol applies to post sales, which provide read and ownership transfer protocol without the need for a backend server to protect the ownership of personal items and personal privacy, when RFID technology become popular in consumers’ lives.