Skip to main content
QUICK REVIEW

[논문 리뷰] A Systematic Security Analysis for Path-based Traceability Systems in RFID-Enabled Supply Chains

Fokke Heikamp, Lei Pan|arXiv (Cornell University)|2026. 01. 14.
Food Supply Chain Traceability인용 수 0
한 줄 요약

본 연구는 RFID 기반 공급망의 경로 기반 추적 가능성에 대한 보안 프레임워크를 제안하고, 17개의 경로 기반 추적 가능성 솔루션을 평가하여 경로 프라이버시 및 순서 이탈 공격 등 여러 취약점을 밝힌다.

ABSTRACT

Traceability systems have become prevalent in supply chains because of the rapid development of RFID and IoT technologies. These systems facilitate product recall and mitigate problems such as counterfeiting, tampering, and theft by tracking the manufacturing and distribution life-cycle of a product. Therefore, traceability systems are a defense mechanism against supply chain attacks and, consequently, have become a target for attackers to circumvent. For example, a counterfeiter may change the trace of a fake product for the trace of an authentic product, fooling the system into accepting a counterfeit product as legit and thereby giving a false sense of security. This systematic analysis starts with the observation that security requirements in existing traceability solutions are often unstructured or incomplete, leaving critical vulnerabilities unaddressed. We synthesized the properties of current state-of-the-art traceability solutions within a single security framework that allows us to analyze and compare their security claims. Using this framework, we objectively compared the security of $17$ traceability solutions and identified several weaknesses and vulnerabilities. This article reports on these flaws, the methodology we used to identify them, and the first security evaluation of traceability solutions on a large scale.

연구 동기 및 목표

  • RFID 기반 추적 가능성 시스템에 대한 구조화된 보안 분석의 필요성을 제시한다.
  • 공간적 및 시간적 경로 특성을 포착하는 경로 기반 추적 가능성을 위한 통합 보안 프레임워크를 정의한다.
  • 경로 기반 공격 및 프라이버시 문제에 대해 17개의 대표적 추적 가능성 솔루션의 보안을 평가한다.
  • 일반적인 약점을 식별하고 보다 안전한 추적 가능성 설계를 위한 통찰을 제공한다.

제안 방법

  • 리더, 태그, 백엔드, 데이터 공유 서버, 발급자를 나타내는 (R, T, B, ds, I) 튜플로 추적 가능성 시스템을 모델링한다.
  • 동작 의미를 추적을 통해 정의하고 경로 기반 특성을 형식화한다: 정당하고, 완전하며, 정렬되고, 허가된 경로.
  • 경로 기반 공격의 분류 체계를 개발하고(순서 이탈, 건너뛰기, 재경로 지정, 유령 단계) 이를 경로 특성에 매핑한다.
  • Dolev-Yao 가정하에 Adv_T(태그 침해) 및 Adv_R(리더 침해) 적대자 모델을 채택하여 보안 주장을 검증한다.
  • 일반적 취약점 식별 후 경로 기반 프레임워크에 대한 형식적 보안 평가의 두 단계 방법론을 적용한다.
Figure 1. Our RFID-enabled Traceability Model
Figure 1. Our RFID-enabled Traceability Model

실험 결과

연구 질문

  • RQ1정당한 추적 가능 시스템에 필요한 필수 경로 기반 보안 속성은 무엇인가?
  • RQ2현실적 적대자 하에서 사운드함, 완전성, 및 허가를 기존 RFID 기반 추적 가능성 솔루션이 어느 정도 충족하는가?
  • RQ3저명한 추적 가능 설계 전반에 걸쳐 어떤 구체적 약점과 공격 벡터가 존재하는가?
  • RQ4하나의 통합 프레임워크가 객관적 비교를 용이하게 하고 안전한 추적 가능 설계를 어떻게 안내할 수 있는가?

주요 결과

  • 17개의 추적 가능 솔루션을 평가하고 여러 약점과 취약점을 식별하였다.
  • 다수의 공격을 발견: RF-Chain의 연계(linking) 공격, Burbridge와 Soppera의 경로 허가 공격, Ray 등과 Tracker의 순서 이탈 공격, ReSC의 키 공개 공격.
  • 모든 시스템이 수동 리더를 이용한 재경로화 공격에 취약했다.
  • 대립적 모델하에서 경로 순서를 강제하거나 전체 경로 문서를 보장하는 데 실패한 솔루션이 많았다.
  • 일부 솔루션은 경로 허가 정책이 어떻게 분배되거나 시행되는지 명확히 설명하지 않았다.
Figure 2. Taxonomy for Path-based Attacks
Figure 2. Taxonomy for Path-based Attacks

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.