Horse-ID
Security of Horse Animal Identification & Registration in The Netherlands
SNE Research Project 1 Laurens Bruinsma Vic Ding
Agenda Introduction Research question System overview - - PowerPoint PPT Presentation
Horse-ID Security of Horse Animal Identification & Registration in The Netherlands SNE Research Project 1 Laurens Bruinsma Vic Ding Agenda Introduction Research question System overview Research methodology
Security of Horse Animal Identification & Registration in The Netherlands
SNE Research Project 1 Laurens Bruinsma Vic Ding
02/11/10 2
Agenda
02/11/10 3
Introduction (1)
animals, like dogs/cats
02/11/10 4
Introduction (2)
02/11/10 6
Introduction (3)
02/11/10 7
Introduction (4)
Goals of the system:
sports and trade
public health →
02/11/10 8
Research Questions
system meet?
improved?
EU PVV Dutch organization Other European
… SPS KWPN VVE … Horse Owner VET Horse Owner VET … …
02/11/10 11
System Overview (2)
– bio-glass or biopolymer encasing – LF fdx-B reader – ISO 11784 & 11785
– 3 digit country code – 1 digit user group / manufacturer – 2 or 3 digit manufacturer pseudo- code – 8 or 9 digit unique code Example : 528000000000000
02/11/10 12
Risk Scenarios
02/11/10 13
Research Methodology (1)
model
02/11/10 14
Research Methodology (2)
02/11/10 15
Research Methodology (3)
02/11/10 16
Research Methodology (4)
02/11/10 17
Findings: Passports (1)
Scenario: Impersonation
– UV visible pattern on paper – stamps – signatures – bar code stickers RFID tag code
02/11/10 18
Findings: Passports (2)
02/11/10 19
Findings: Procedures
Scenario: Impersonation Procedures: – no security measures blank passports – no copy of ID applicant needed – passports of dead horses not always returned
02/11/10 20
Findings: RFID (1)
Scenario: Impersonation RFID tag: – no protection built in chip – eavesdropping easy but not interesting – covert read out: read distance varies – cloning easy
02/11/10 21
Findings: RFID (2)
Scenario: Tag gets permanently disabled – difficult to remove – “flashing” is possible – different size, different antenna – glass tag more energy → required
02/11/10 22
Findings: RFID (3)
Scenario:Tag/reader gets temporarily disabled
– no read out
– possible but not necessary
02/11/10 23
– reader, functionally poor – tag, insecure
– Poor document security – Poor security for blank passports
– mostly unknown – No easy check of identity for public
– On paper, but enforcement troublesome – Many individual organizations
02/11/10 24
General:
passport issuing and registration RFID tags & readers:
– Using public/private key pair + challenge/response – Protection against cloning
02/11/10 25
regularly
passport of dead horse
new or replacing passport
02/11/10 26
identities
RFIDiot.org
./readlfx.py
./fdxnum.py
national level
02/11/10 28