Wireless IT and RF Infrastructure for Stores

4125 Words9 Pages

1. Introduction

This document discusses the security implications of the proposed new wireless IT infrastructure for Stores. This document primarily focuses on issues related to the risk of adopting pre-shared keys for authenticating devices, as the risks associated with the end user devices are documented elsewhere.

The following is extracted from the TAD:

Currently there are a number of store devices and applications that rely on the existing Stores RF Infrastructure. The current RF systems were first deployed in stores several years ago. The supplier of these systems, Symbol Technologies has announced end-of-life for all products that comprise the current Stores RF Infrastructure.

Based upon current store opening plans an amount of stock was purchased and stockpiled prior to the Last Purchase date which should provide enough Frequency Hopping equipment to cover replacements and new store openings until the end of May 2007; however this has recently been reduced to the end on Feb 2007. After this date, opening stores with the old RF technology will not be possible.

2. Current Environment

The following is extracted from the TAD:

The security implemented within the existing stores RF environment relies on three elements; the fact that the technology used is quite obscure, the fact that the frequency changes frequently and the fact that a MAC address list is implemented through the use of an in-house application called Hyena.

The Frequency Hopping wireless network makes use of a technology which allows the FH enabled wireless devices and the FH Access Points to switch frequencies simultaneously at regular rapid intervals. This makes capturing or sniffing conversations tricky and would mean that anyone wis...

... middle of paper ...

...

Additionally if the key on any device of a particular type that falls under PCI is suspected of being compromised then an incident needs to be raised and the incident response plan followed, probably resulting in the keys on all devices of that type being changed immediately to maintain M&S’s compliance.

IPOS-08

The current planned dates for the I-POS 08 delivery indicate that new hardware will begin to be deployed to the stores between September and October this year and with a completion date of mid-08 for the tills. Along with the new hardware an operating system upgrade to XP/Vista for desktops and WePOS for the tills will be undertaken at the same time. As these new devices will offer more support for a certificate based solution it is essential that a programme of work is undertaken to allow this to be developed and deployed with the new rollouts.

Open Document