DHS report faults use of RFID for human identification
Says threat to privacy outweighs benefits
Computerworld - A committee of the U.S. Department of Homeland Security next week will consider a report that criticizes the use of radio frequency identification (RFID) technology for security authentication.
The report, now in draft form (PDF), was prepared by the DHS’s Emerging Applications and Technology subcommittee. A final version is to be presented Wednesday at a meeting of the DHS’s Data Privacy and Integrity Advisory Committee, which advises the secretary of DHS and his chief privacy officer.
While the authors of the report acknowledge that RFID is useful for such tasks as inventory management, the report said that the technology, overall, is undesirable for processes connected with people. The benefits of its support for rapid communication over distances and its uses in security are outweighed by its risks to privacy, the report stated.
"Most difficult and troubling is the situation in which RFID is ostensibly used for tracking objects (medicine containers, for example), but can be in fact used for monitoring human behavior. These types of uses are still being explored and remain difficult to predict. For these reasons, we recommend that RFID be disfavored for identifying and tracking human beings," the report said.
Howard Beales, the committee chairman, noted that the report has garnered more public response than usual. The report remains a work in progress, he said, and after being discussed next week, it will probably be returned to the subcommittee for more revisions.
Any formal recommendation to Homeland Security Secretary Michael Chertoff will probably wait until September or December, when the committee holds its quarterly meeting. "I think RFID in general is a very interesting technology," Beales said, but added that "it can raise privacy concerns." He said these are the sorts of issues the committee and subcommittee will consider.
The report points out that some believe that an RFID system could be a way of rapidly authenticating an individual and ensuring that a user identification document, such as a passport, is valid. However, the report said that an RFID system can’t necessarily verify who an individual is. That could be done only by having the RFID tag tied to a unique biometric characteristic, such as a fingerprint. This would still require a manual verification process, and any speed benefits from using RFID would be marginal, the report said.
The report noted that the State Department required that e-passports equipped with RFID tags be swiped through a reader and that a personal PIN be used for authentication. "This welcome personal security measure adds back the delay and inefficiency that RFID technology was designed to overcome, obviating the utility of RFID for this application," the report states.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Digital Transformation: Creating New Business Models Where Digital Meets Physical
- Individuals and businesses alike are embracing the digital revolution. Social networks and digital devices are being used to engage government, businesses and civil...
- Empowering Your Mobile Worker
- Today's most productive employees are mobile, and your company's IT strategy must be ready to support them with 24/7 access to the business...
- An Interactive Guide: Bring Your Own Device
- BYOD presents significant security and management challenges to IT departments who want to take advantage of the trend, but still protect corporate assets....
- Calculating ROI for Mobile Client Acceleration
- As mobile devices continue to expand in business use, ensuring these devices have optimal performance is becoming an IT imperative. This EMA paper...
- Tablet Computing Without Compromise
- This paper provides an overview of how and why that migration-from any old tablet to Windows tablets-came to be. All Mobile and Wireless White Papers
- Live Webcast
North Pole to South Seas: Overcoming the Pitfalls of remote Performance - In today's always-on world, connectivity is a business requirement. You need the tools that allow you to operate as if you were on...
- Supporting Mobile Productivity With A Limited IT Budget
- Join us and hear from Kaseya mobile IT management experts as we discuss core strategies for supporting the mobile revolution on a shoestring...
- North Pole to South Seas: Overcoming the Pitfalls of remote Performance
- In today's always-on world, connectivity is a business requirement. You need the tools that allow you to operate as if you were on...
- Unified Communications 101
- What's the best way to implement a unified communications solution for your organization?
- QNX® and BlackBerry® PlayBook™ Tablet.
- RIM's multi-processor, multi-tasking BlackBerry PlayBook runs a new Tablet OS powered by QNX, a bullet-proof microkernel operating system. This track will take a...
- A Close Look at Tablets
- Learn More All Mobile and Wireless Webcasts