Radio-frequency identification (RFID)

Identification of tagged objects, badges or people by radio: a reader energises or queries a tag and receives its identifier, often without line of sight or the holder's awareness.

Radio-frequency identification (RFID) uses radio signals to read an identifier from a tag on an object or card. A passive tag has no battery and draws its power from the reader’s field, which keeps it cheap and gives it a shorter read range; an active tag carries its own power source and can be read from further away. Typical uses include inventory tracking and physical access badges. NIST SP 800-98, the guide to securing RFID systems, covers the tags and readers together with the enterprise systems behind them.

The recurring threats follow from the radio link. Skimming is reading a tag without the holder’s consent, eavesdropping captures a legitimate exchange, and cloning copies a tag’s identifier onto a new tag, which defeats an access badge that only presents a fixed number. Tracking is a privacy risk even when the tag data is harmless. Controls commonly include shielded holders and tags that authenticate cryptographically rather than replaying a static value. Near-field communication builds on some RFID standards and adds two-way exchange between devices.

Exam relevance: a scenario about copied badges or covert tag reading is likely to turn on RFID skimming or cloning. Candidates are expected to know that a fixed identifier can be copied, and that short range reduces the risk without removing it.