Friday, September 01, 2006

California Passes RFID Legislation


California's Assembly has just passed bill S768, a piece of legislation that sets out the security guidelines that RFID-equipped state documents must meet.

The bill, subtitled the Identity Information Protection Act of 2006, gives guidelines for RFID documents produced until December 31, 2012 - at which point the requirement will apparently be reviewed and updated.

It affects all IDs issued by "a state, county, or municipal government, or subdivision or agency thereof, that use radio waves to transmit data or to enable data to be read remotely," and forces them to incorporate certain safeguards. First, the documents must implement a mutual authentication process with the card reader in order to prevent data being grabbed from nearby, unauthorized readers. Second, all data must be encrypted or otherwise rendered "unreadable and unusable by an unauthorized person" while in transit. Third, and perhaps most interesting, is the requirement that the transmission of any personally identifiable information be placed under the owner's sole control.

0 Comments:

Post a Comment

<< Home