Layers can be decomposed to attain greater detail. Similarly, partitions can be decomposed into minor partitions. As partitions are an additional concept for representational approaches to RFID security, this section illustrates several minor partitions to show how partition decomposition can proceed
Figure 16 depicts the standard operating partition with the inclusion of three minor partitions. These have organised the standard components to consider: the components, their associations with each other, and the information which can be gained through their interactions, as separate concepts. These were derived using the various analysis methods discussed in Chapter 4, however, this section of the thesis backtracks slightly in order for the later chapters to make sense. Three minor partitions are introduced: components, associations, and features. The elements of these minor partitions will be further explored in the next chapter.
C o m p o n e n ts A sso ci a ti o n s F e a tu re s C o m p o n e n ts A sso ci a ti o n s F e a tu re s
Figure 16 - The reference model showing minor partitions
These minor partitions are vertical decompositions of the major partitions as a way of achieving more security detail.
The components partition comprises the logical view of the RFID domain such as:
physical entities; tags; readers; middleware; and a system’s information goals. It focuses on the representation of discrete objects which would have attributes and
component would be a drug entity, whereas, at the RFID layer, a component would be a tag or reader. Thus, each object would have a logical template from which it is instantiated in this minor partition. In the next chapter Object Oriented Analysis (OOA) and the Unified Modelling Language (UML) (Bruegge and Dutoit 2004; Maciaszek and Liong 2005) are used to represent the components of this minor partition.
The associations partition comprises the data view which emerges when components
in the component partition interact. These associations could be permanent associations if objects are associated with each other for the duration of their lifetime – such as the assembly of ingredients of a drug entity – or they could be temporary associations – such as the association which forms when a physical entity introduces a tag entity to a reader entity. In the next chapter, a formalisation of these
associations for the RFID data layer will be introduced using Entity-Relationship
Diagram (ERD) methods (Pressman 2000).
Finally, the feature partition represents metrics which can be constructed from the data associations between components in the previous two partitions. While there could be observable features at any of the layers, the next chapter will demonstrate the advantages which are imparted when features are constructed at the data layer. Manual knowledge driven feature construction approaches (Wnek and Michalski 1994) will be used to derive new features without the need to add additional systems context, illustrating how this partition can be analysed.
In this way the integration of minor partitions serves to enhance the granularity of analysis.
5.2.2.5
A
BSTRACTIONP
RINCIPLESO
FT
HEM
ODELI
NM
INORP
ARTITIONO
RDERINGThe decomposition of minor partitions follows a simple principle that minor partitions should be abstracted such that the left-most minor partition is the most concrete, and the right-most partition is the most abstract. For example, for the standard operating partition: the association partition emerges from the components
In this way, what is analysed occurs across increasing levels of abstraction – from the most concrete concepts (the extreme left) to the most abstract concepts (the extreme right). This is illustrated in Figure 17 through the use of arrows which are directed from the bottom left corner to the top-most right corner, and vice versa.
Real World for Interconnection Standard Operating Partition Problem Partition Solution Partition Standard Operating Partition Problem Partition Solution Partition System A System B
Figure 17 - The inclusion of minor-partitions follows an abstraction paradigm
Abstraction of details across the minor partitions should be from most specific to least specific in order to facilitate abstraction across system layers.
The reason for this depiction is now explained. If one was to examine a major partition which had been decomposed using minor partitions, with the inclusion of layers, it would be apparent that in examination from the real world layer’s bottom left-most corner, to the strategic layer’s top-most right corner, a diagonal direction would be followed. This convention is intended to convey the degree of abstraction of RFID systems. That is, some systems abstract the environment more in terms of the number of layers between the real world layer and strategic layer – the Electronic Product Code (EPC) system which uses the Object Name Services (ONS) is one such system (Ranasinghe et al. 2008) – the ONS is a data layer which fits over the RFID. Thus, this model has a strong representational basis for actual RFID systems – a feature which was not facilitated by previous work examined in Chapter 3.
many layers and partitions between the source of attack and the attack destination, could offer more points for security solutions, in addition to more points of attack. This approach to abstraction is a feature unique to this model when compared to previous work.
To briefly summarise, the use of a vertical partition property strongly distinguishes this reference model from previous work. Partitions enable the separation of independent but related security concepts – standard operations, threats, and solutions. The advantage imparted is that security is analysed across three major concepts in a system, making analysis more structured than if just threats or solutions were to be considered without relation to one another.
5.2.3
I
NTEGRATINGL
AYERS ANDP
ARTITIONSThe integration of layer and partition properties enables a closer comparison
between the RFID system and RFID security. This was a major shortcoming which was apparent in previous work which was reviewed in Chapter 3. This section explains how integration addresses this shortcoming, and consequently, makes possible a ‘whole of system’ approach to the analysis of security in RFID systems. The integrated layered and partitioned reference model is reintroduced in Figure 18, in its complete form. In this diagram it can be seen that the layers have been divided using the partitions. This is where the integration of these properties is depicted. Although there is a small separation between the layers, the partitions span all the layers, thereby enabling the derivation of security concepts under a single partition, across all three major layers.
To this end, the standard operating partition should be thought of as spanning the
strategic layer, RFID layer, and the real world layer. The minor partitions have
been included in the diagram; however, the use of these minor partitions is only illustrative of this integration concept – minor layers are in effect optional. Similarly, the use of the OSI layers at the RFID layer has not been depicted; however these could be added when the model is applied to real analysis problems. The rest of this section expounds the reasons for this integration.
Figure 18 - The integrated layered and partitioned reference model
The model is reintroduced in this section having explained the properties of layers and partition separately.
Integration makes it possible to analyse partition concepts across layers of an RFID system. For example, the standard operating partition can model: the physical entities and physical constraints at the real world layer; at the RFID layer (the RFID components such as tags and readers, anti-collision and other protocols); and at the strategic layer (the information goals of the company whether these are monitoring or authorisation). Integration enables ‘whole of system’ analysis in each partition across system layers.
Through the integration of both properties, it is possible to consider RFID and security concepts collectively. For example, the standard operating partition can be used to consider how the strategic layer information goals of monitoring or authorisation are being facilitated by the RFID components, and whether these components are integrated within the real world layer adequately to achieve these information goals. For the other partitions, the same approach can be used to take a systematic view of the concepts they represent.
An approach which considers interrelationships is enabled as the major partitions are aligned to each other. Comparisons can be made between partitions but at different layers. For example, the solution partition could model solutions at the strategic layer, and these could be compared to the problems which occur at the same layer of the problem partition. Whether modelled solutions and problems are in fact feasible
partition at the strategic layer as well. Thus, integration of layers and partitions facilitates a ‘whole of system’ approach to the analysis of security in RFID systems. It is therefore possible to compare partitions to each other across all of the system layers. Integrated security analysis is therefore achievable. Questions can be proposed and answered along the lines of:
• How can solutions at the strategic layer address threats which occur in the RFID layer in an actual system?
• How will the choice of anti-collision protocols influence which threats may be possible in a system?
• How will a system’s real world layer influence which attacks are feasible in the RFID layer?
To this end, the integration of layers and partitions enables effective security requirements analysis to be undertaken. It would be possible to consider security questions which are created across all facets of the system rather than on individual components.
5.3
SUMMARY
This chapter has introduced an alternative model for the analysis of security using a ‘whole of system’ approach. It was constructed using the reference model paradigm reviewed in Chapter 4. It is distinguished from previous work (see Chapter 3) on the basis of integrated layer and partition properties, and has therefore been entitled, An
Integrated Layered and Partitioned Reference Model. The integration of these
properties is expected to be more conducive to a ‘whole of system’ approach to analysis when compared to the examples of previous work.
Recall that there were some apparent limitations on previous work which the design and intended use of the proposed model addresses. The model proposed by Rotter (2008) does not appear to be suitable for analysis beyond several system properties. Conversely, the model proposed by Mitrokotsa et al. (2010) allows for the use of security principles and attributes only within individual layers, thereby reducing its generality.
As it seems that previous work has been localised to specific system properties, which has the drawback of missing the interrelationships which are relevant throughout the ‘whole system,’ the concept of integrating layers and partition properties was introduced in the proposed model.
The horizontal system layer property captures system components at a relatively high level of abstraction. One advantage is the ability to encapsulate previous work within representations of system layers. The organisation of these layers, with the RFID layer in the centre, suggests that RFID is a central concept, but should be viewed in conjunction with the real world layer and the strategic layer. Conversely,
the partition property facilitates a means of analysing security in the RFID domain.
Partitions demarcate the domain such that solutions can be evaluated against particular threats, in particular system contexts. The organisation of layers, from the least abstract to the most abstract imparts the principle that analysis is based on what a system functionally supports. Attacks and solutions are then related to the systems functions.
The integration of layer and partition properties provides an option to use the model for complete ‘whole of system’ analysis of security. Whether analysis has proceeded per layer or partition, the outcomes of analysis through the model should mean that an effective view of security can been taken. The discussion in Chapter 2 suggested that could be a desirable approach to take, as cloning and constraints have system wide influences. Integration allows all of these interrelationships to be taken into consideration during analysis.
The following chapters will illustrate that when this model is used, structured security analysis can be achieved:
• Chapter 6 illustrates how analysis using the standard operating partition facilitates the enumeration of system elements into a domain model.
• Chapter 7 illustrates how analysis using the problem partition enables systematisation of attacks.
• Chapter 8 introduces a simulator model and demonstrates through its use the benefits of taking a systems approach to solution analysis in the solution partition.
• Chapter 9 demonstrates, through experimentation, how the model facilitates systems analysis prior to solution deployment.
• Chapter 10 validates the ‘whole of system’ approach in the context of the specific example of a pharmaceutical supply chain.
The work presented in these chapters will show that the reference model improves on previous work by providing more structured security analysis.