<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article  PUBLIC "-//NLM//DTD Journal Publishing DTD v3.0 20080202//EN" "http://dtd.nlm.nih.gov/publishing/3.0/journalpublishing3.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="3.0" xml:lang="en" article-type="research article"><front><journal-meta><journal-id journal-id-type="publisher-id">AIT</journal-id><journal-title-group><journal-title>Advances in Internet of Things</journal-title></journal-title-group><issn pub-type="epub">2161-6817</issn><publisher><publisher-name>Scientific Research Publishing</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.4236/ait.2012.22005</article-id><article-id pub-id-type="publisher-id">AIT-18636</article-id><article-categories><subj-group subj-group-type="heading"><subject>Articles</subject></subj-group><subj-group subj-group-type="Discipline-v2"><subject>Computer Science&amp;Communications</subject></subj-group></article-categories><title-group><article-title>
 
 
  Evaluation of Different Electronic Product Code Discovery Service Models
 
</article-title></title-group><contrib-group><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>u</surname><given-names>Mon Kywe</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref><xref ref-type="corresp" rid="cor1"><sup>*</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Jie</surname><given-names>Shi</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref><xref ref-type="corresp" rid="cor1"><sup>*</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Yingjiu</surname><given-names>Li</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref><xref ref-type="corresp" rid="cor1"><sup>*</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Raghuwanshi</surname><given-names>Kailash</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref><xref ref-type="corresp" rid="cor1"><sup>*</sup></xref></contrib></contrib-group><aff id="aff1"><addr-line>School of Information Systems, Singapore Management University, Singapore City, Singapore</addr-line></aff><author-notes><corresp id="cor1">* E-mail:<email>monkywe.su.2011@smu.edu.sg(UMK)</email>;<email>jieshi@smu.edu.sg(JS)</email>;<email>yjli@smu.edu.sg(YL)</email>;<email>kailashr@smu.edu.sg(RK)</email>;</corresp></author-notes><pub-date pub-type="epub"><day>24</day><month>04</month><year>2012</year></pub-date><volume>02</volume><issue>02</issue><fpage>37</fpage><lpage>46</lpage><history><date date-type="received"><day>December</day>	<month>21,</month>	<year>2011</year></date><date date-type="rev-recd"><day>January</day>	<month>19,</month>	<year>2012</year>	</date><date date-type="accepted"><day>February</day>	<month>4,</month>	<year>2012</year></date></history><permissions><copyright-statement>&#169; Copyright  2014 by authors and Scientific Research Publishing Inc. </copyright-statement><copyright-year>2014</copyright-year><license><license-p>This work is licensed under the Creative Commons Attribution International License (CC BY). http://creativecommons.org/licenses/by/4.0/</license-p></license></permissions><abstract><p>
 
 
  Electronic Product Code Discovery Service (EPCDS) is an important concept in supply chain processes and in Internet of Things (IOT). It allows supply chain participants to search for their partners, communicate with them and share product information using standardized interfaces securely. Many researchers have been proposing different EPCDS models, considering different requirements. In this paper, we describe existing architecture designs of EPCDS systems, namely Directory Service Model, Query Relay Model and Aggregating Discovery Service Model (ADS). We also briefly mention Secure Discovery Service (SecDS) Model, which is an improved version of Directory Service Model with a secure attribute-based access control mechanism. Then, we analyze the strengths and limitations of these models, by comparing based on non-functional features such as data ownership, confidentiality, business relationship independence, availability, reliability, implementation complexity, visibility, and scalability. From the analysis results, we have a better understanding of which model is more suitable in what kinds of situations or scenarios. Moreover, we suggest possible improvements and identify possible future add-on applications to SecDS model in the paper.
 
</p></abstract><kwd-group><kwd>EPC Discovery Service; Supply Chain; Access Control; Comparison</kwd></kwd-group></article-meta></front><body><sec id="s1"><title>1. Introduction</title><p>Supply chain is a process of transforming natural resources or raw materials into finished goods, by passing through suppliers, manufacturers, wholesalers, retailers, customers and other supply chain partners [<xref ref-type="bibr" rid="scirp.18636-ref1">1</xref>]. When various supply chain partners work together to deliver the right amount of goods to the right customers at right time and right place, good coordination and information sharing are critical.</p><p>Lack of information sharing among supply chain partners can lead to a lot of negative consequences. For instance, when downstream retailers are not willing to share their end customer information (e.g. for security and privacy reasons), upstream suppliers and manufacturers have no idea about the customers. The manufacturers predict the customer demand from wholesalers’ orders, while wholesalers predict the customer demand from the retailers’ orders. This lack of information transparency can lead to “bullwhip effect” where each upstream supply chain participant observes greater demand variation and greater need for safety stocks, consequently bearing greater costs [<xref ref-type="bibr" rid="scirp.18636-ref2">2</xref>]. The whole supply chain can suffer as it becomes less responsive to demand fluctuations.</p><p>Therefore, in today’s market where competition is very intense, it becomes increasingly important to have a structured way of fast and secure information sharing among supply chain partners. Standardized systems and communication methods, which can be used uniformly across different organizations around the globe, are required to be developed.</p><p>As such, EPCglobal organization [<xref ref-type="bibr" rid="scirp.18636-ref3">3</xref>], which is responsible for standardization of Electronic Product Code (EPC) technology [<xref ref-type="bibr" rid="scirp.18636-ref4">4</xref>], created EPCglobal Network [<xref ref-type="bibr" rid="scirp.18636-ref5">5</xref>] for sharing RFID information. EPCglobal Network is implemented, using standards from EPCglobal Architecture Framework [<xref ref-type="bibr" rid="scirp.18636-ref6">6</xref>]. It has four components, namely Object Naming Service (ONS), EPC Discovery Services (EPCDS), EPC Information Services (EPCIS) and EPC Security Services [<xref ref-type="bibr" rid="scirp.18636-ref5">5</xref>]. In this paper, we focus mainly on EPCDS models, since standardization of EPCDS design is still an open research question [<xref ref-type="bibr" rid="scirp.18636-ref6">6</xref>].</p><p>Our paper is structured as follows. Section 2 provides background information on EPCDS and EPCIS. Section 3 briefly describes existing EPCDS models which include Directory Service Model, Query Relay model and Aggregating Discover Service model. In Section 4, we describe SecDS model which is an extension of Directory Service Model. Section 5 gives comparison of the different models and Section 6 summarizes the analysis. Then, we identify possible improvements for SecDS model in Section 6 and finally we conclude the paper in Section 7 with the role of EPCDS in future Internet of Things (IOT) [<xref ref-type="bibr" rid="scirp.18636-ref7">7</xref>].</p></sec><sec id="s2"><title>2. Background</title><sec id="s2_1"><title>2.1. EPCDS</title><p>Electronic Product Code Discovery Service (EPCDS) is a service that allows users to find supply chain partners who possess a given product. A user just need to key in a particular EPC number, such as RFID number of the product, to search for EPC Information Services (EPCIS) provided by the related supply chain partners within the network.</p><p>EPCDS can be compared to telephone directory or search engines of the internet. To request information about a particular EPC, a supply chain participant needs to have knowledge of who are its supply chain partners and their network addresses or URLs that should be queried. This is like the need to know the phone numbers before contacting each other. Then, EPCDS acts like a telephone directory or yellow page where the contacts or addresses of EPC information providers or repositories are aggregately stored and returned to the appropriate queries accordingly, as shown in <xref ref-type="fig" rid="fig1">Figure 1</xref> [<xref ref-type="bibr" rid="scirp.18636-ref8">8</xref>].</p><p>Basically, EPCDS supports two operations, publishing operation and querying operation. Publishing operation is for EPCIS to publish their information on EPCIS whereas querying operation is for supply chain users, who want to find published EPCIS addresses.</p></sec><sec id="s2_2"><title>2.2. EPCIS</title><p>In this context, EPC Information Service (EPCIS) can simply be viewed as a database or repository owned by a supply chain participant. It stores event information of supply chain products, where each product is uniquely identified by an EPC number. EPC event information includes product information, product location, date and time of product arrival and departure, involved business processes, and other important business information [<xref ref-type="bibr" rid="scirp.18636-ref6">6</xref>].</p><p>To share its critical business information with its trusted supply chain partners, EPCIS provides a querying</p><p>interface for its repository. However, EPCIS may maintain access control mechanisms to ensure that only authorized users can access its sensitive information. With EPCIS querying service, any authorized users, who know the address of EPCIS service, can get access to its EPC repositories or databases easily.</p></sec><sec id="s2_3"><title>2.3. Definition of Terms</title><p>In our paper, the terms “users” or “clients” is used for supply chain participants who want to get EPC event information from EPCIS. EPCIS company (owner), database and its services are collectively mentioned as “EPCIS”, “resource”, “EPCIS resource” “EPCIS repository” or “EPCIS company”.</p></sec></sec><sec id="s3"><title>3. Existing Discovery Service Models</title><p>BRIDGE (Building Radio frequency identification for the Global Environment) project has modeled and analyzed eight possible high level designs of EPCDS in 2007. After considering each model’s feasibility, BRIDGE selected the two models of EPCDS, called Directory Service Model and Query Relay Model [<xref ref-type="bibr" rid="scirp.18636-ref8">8</xref>]. Although there are a lot of variations of these two models, our paper only use basic models suggested in BRIDGE document for simplicity purpose. The third EPCDS design is Aggregating Discovery Service (ADS) Model, proposed by Hasso Plattner Institute for IT Systems Engineering in 2010 [<xref ref-type="bibr" rid="scirp.18636-ref9">9</xref>].</p><sec id="s3_1"><title>3.1. Directory Service Model</title><p>In Directory Service Model, EPCDS stores a directory of EPC numbers and corresponding EPCIS addresses. <xref ref-type="fig" rid="fig2">Figure 2</xref> illustrates the steps of this Directory Service Model.</p><p>Step 1: An owner of an EPCIS first registers at EPCDS with the details on which EPC numbers they are handling, together with its service address or URL. EPCDS stores the pairs of EPC numbers and EPCIS addresses in its lookup table.</p><p>Step 2: User sends query to EPCDS with a specific EPC number or a range of EPC numbers as parameters.</p><p>Step 3: EPCDS uses lookup table to look up queried EPC numbers, finds corresponding EPCIS addresses and returns them to the user.</p><p>Step 4: With the returned addresses, the user queries directly to EPCIS repositories to get the desired required EPC event information.</p><p>Step 5: EPCIS repositories return the required EPC event information to the user.</p><p>One of the main problems of Directory Service Model is that EPCDS returns all the related EPCIS addresses to every user who queries. Access control mechanisms are not specified in detail.</p><p>Based on the query result, every user knows exactly which EPCIS repositories are handling which EPC numbers. Availability of EPCIS addresses indicates ownership of product information in that EPCIS companies. Therefore, many companies, who consider their possession of items as confidential or sensitive information, do not want to expose their EPCIS addresses and are reluctant to publish them on EPCDS.</p></sec><sec id="s3_2"><title>3.2. Query Relay Model</title><p>In the query relay model, EPCDS does not return the service addresses of EPCIS repositories immediately upon request. Instead, it redirects the query to corresponding EPCIS repositories which have their own access control mechanisms. As shown in <xref ref-type="fig" rid="fig3">Figure 3</xref>, query relay model has the following steps.</p><p>Step 1: An owner of an EPCIS first registers at EPCDS with the details on which EPC numbers they are handling, together with its service address or URL. Then, EPCDS stores the pairs of EPC numbers and EPCIS addresses in the lookup table.</p><p>Step 2: User sends query to EPCDS with a specific EPC number or a range of EPC numbers as well as user’s credentials as parameters.</p><p>Step 3: EPCDS uses lookup table to look up queried EPC numbers, finds corresponding EPCIS addresses and relays user’s query and credentials to those EPCIS resources.</p><p>Step 4: Each EPCIS resource checks user’s credentials against its own access control database and returns the query result to the authenticated user directly.</p><p>Actually, in query relay model, user query can be of two types. The first one is a full query, directly requesting EPCIS to return the full EPC event information. The second query type is a resource query, where EPCIS returns only the service address that user should query to</p><p>get required EPC event information.</p></sec><sec id="s3_3"><title>3.3. Aggregating Discovery Service (ADS)</title><p>Aggregating Discovery Service (ADS) model is based on the query relay model. In this model, instead of returning EPC event information directly to user, each EPCIS returns the result back to EPCDS. Only after getting replies from different EPCIS repositories, EPCDS aggregates their information and sends them back to the user. <xref ref-type="fig" rid="fig4">Figure 4</xref> shows the steps of aggregating discovery service model.</p><p>Step 1: An owner of an EPCIS first registers at EPCDS with the details on which EPC numbers they are handling, together with its service address or URL. Then, EPCDS stores the pairs of EPC numbers and EPCIS addresses in the lookup table.</p><p>Step 2: User sends query to EPCDS with a specific EPC number or a range of EPC numbers as well as user’s credentials as parameters.</p><p>Step 3: EPCDS uses lookup table to look up queried EPC numbers, finds corresponding EPCIS addresses and relays user’s query and credentials to those EPCIS resources.</p><p>Step 4: Each EPCIS resource checks user’s credentials against its own access control database and returns the query result to EPCDS.</p><p>Step 5: EPCDS aggregates the results and relays them back to the user.</p></sec></sec><sec id="s4"><title>4. Secure Discovery Service Model</title><p>Secure Discovery Service model (SecDS) is based on Directory Service Model.</p><p>As described in Section 3.1, Directory Service Model has a critical problem due to the lack of access control system in EPCDS. Sensitive business information may be leaked, since EPCDS returns related EPCIS addresses to every user query.</p><p>In SecDS model, the basic Directory Service Model is improved by implementing a secure access control mechanism inside EPCDS. Access control mechanism in EPCDS makes sure that it does not release EPCIS addresses to any unauthorized users. Confidentiality of important EPC information is preserved.</p><p>As shown in <xref ref-type="fig" rid="fig5">Figure 5</xref>, steps in SecDS model are the same as steps in Directory Service Model, except that in</p><p>step 1, access control policies are sent together with EPC numbers and EPCIS address from EPCIS. In addition to lookup table of EPCIS addresses, EPCDS maintain a database on access control policies in SecDS model.</p><p>Moreover, EPCDS provides interfaces for adding, deleting and modifying access control policies. EPCIS owners can use these interfaces to synchronize access control polices between EPCDS and EPCIS.</p><sec id="s4_1"><title>4.1. Architecture of SecDS Model</title><p><xref ref-type="fig" rid="fig6">Figure 6</xref> describes the overview EPCDS architecture of SecDS model with attribute-based access control system [<xref ref-type="bibr" rid="scirp.18636-ref10">10</xref>].</p></sec></sec></body><back><ref-list><title>References</title><ref id="scirp.18636-ref1"><label>1</label><mixed-citation publication-type="other" xlink:type="simple">Wikipedia, “Supply Chain,” 2011.  
http://en.wikipedia.org/wiki/Supply_chain </mixed-citation></ref><ref id="scirp.18636-ref2"><label>2</label><mixed-citation publication-type="other" xlink:type="simple">Wikipedia, “Bullwhip Effect,” 2011.  
http://en.wikipedia.org/wiki/Bullwhip_effect </mixed-citation></ref><ref id="scirp.18636-ref3"><label>3</label><mixed-citation publication-type="other" xlink:type="simple">Wikipedia, “EPCglobal,” 2010.  
http://en.wikipedia.org/wiki/EPCglobal</mixed-citation></ref><ref id="scirp.18636-ref4"><label>4</label><mixed-citation publication-type="other" xlink:type="simple">Wikipedia, “Electronic Product Code,” 2011.  
http://en.wikipedia.org/wiki/Electronic_Product_Code</mixed-citation></ref><ref id="scirp.18636-ref5"><label>5</label><mixed-citation publication-type="other" xlink:type="simple">Wikipedia, “EPCglobal Network,” 2010.  
http://en.wikipedia.org/wiki/EPCglobal_Network</mixed-citation></ref><ref id="scirp.18636-ref6"><label>6</label><mixed-citation publication-type="other" xlink:type="simple">EPCGlobal, “The EPCglobal Architecture Framework,” 2010.  
http://www.gs1.org/gsmp/kc/epcglobal/architecture/architecture_1_4-framework-20101215.pdf </mixed-citation></ref><ref id="scirp.18636-ref7"><label>7</label><mixed-citation publication-type="other" xlink:type="simple">Wikipedia, “Internet of Things,” 2012.  
http://en.wikipedia.org/wiki/Internet_of_Things</mixed-citation></ref><ref id="scirp.18636-ref8"><label>8</label><mixed-citation publication-type="other" xlink:type="simple">University of Cambridge, AT4 Wireless, BT Research, SAP Research (BRIDGE project), “High Level Design for Discovery Services,” 15 August 2007.  
http://www.bridge-project.eu/data/File/BRIDGE%20WP02%20High%20level%20design%20Discovery%20Services.pdf</mixed-citation></ref><ref id="scirp.18636-ref9"><label>9</label><mixed-citation publication-type="other" xlink:type="simple">J. Muller, J. Oberst, S. Wehrmeyer, J. Witt, A. Zeier and H. Plattner, “An Aggregating Discovery Service for the EPCglobal Network,” Proceedings of the 43rd Hawaii International Conference on System Sciences, Hawaii, 5-8 January 2010, pp. 1-9.</mixed-citation></ref><ref id="scirp.18636-ref10"><label>10</label><mixed-citation publication-type="other" xlink:type="simple">S. Jie, D. Sim and L. Yingjiu, “SecDS: A Secure EPC Discovery Services System in EPCglobal Network,” 2nd ACM Conference on Data and Application Security and Privacy (CODASPY), San Antonio, 7-9 February 2012, pp. 267-274.</mixed-citation></ref><ref id="scirp.18636-ref11"><label>11</label><mixed-citation publication-type="other" xlink:type="simple">C. Kürschner, C. Condea, O. Kasten and F. Thiesse, “Discovery Service Design in the EPCglobal Network: Towards Full Supply Chain Visibility,” Proceedings of the 1st International Conference on the Internet of Things,” Zurich, 26-28 March 2008, pp. 19-34.</mixed-citation></ref><ref id="scirp.18636-ref12"><label>12</label><mixed-citation publication-type="other" xlink:type="simple">E. Polytarchos, S. Eliakis, D. Bochtis and K. Pramatari, “Evaluating Discovery Services Architectures in the Context of the Internet of Things,” Unique Radio Innovation for the 21st Century, Part 3, 2010, pp. 203-227.</mixed-citation></ref><ref id="scirp.18636-ref13"><label>13</label><mixed-citation publication-type="other" xlink:type="simple">E. Sergei, F. Benjamin, K. Steffen and S. Nina, “Comparison of Discovery Service Architectures for the Internet of Things,” Proceedings of the 2010 IEEE International Conference on Sensor Networks, Ubiquitous, and Trustworthy Computing, Newport Beach, 7-9 June 2010, pp. 237-244. doi:10.1109/SUTC.2010.22</mixed-citation></ref><ref id="scirp.18636-ref14"><label>14</label><mixed-citation publication-type="other" xlink:type="simple">Afilias, “Finding Your Way in the Internet of Things,” 2008. http://www.afilias.info/webfm_send/11</mixed-citation></ref><ref id="scirp.18636-ref15"><label>15</label><mixed-citation publication-type="other" xlink:type="simple">K. Framling, M. Harrison and J. Brusey, “Globally Unique Product Identifiers—Requirements and Solutions to Product Lifecycle Management,” Proceedings of 12th IFAC Symposium on Information Control Problems in Manufacturing (INCOM), Ecole des Mines, Saint Etienne, 17-19 May 2006, pp. 17-19.</mixed-citation></ref><ref id="scirp.18636-ref16"><label>16</label><mixed-citation publication-type="other" xlink:type="simple">B. Fabian, “Implementing Secure P2P-ONS,” Proceedings IEEE International Conference on Communications, Dresden, 14-18 June 2009, pp 988-992.</mixed-citation></ref><ref id="scirp.18636-ref17"><label>17</label><mixed-citation publication-type="other" xlink:type="simple">ISO, “Software Engineering—Product Quality—Part 1: Quality Model,” 2001. ISO/IEC TR 9126-1:2001</mixed-citation></ref></ref-list></back></article>