2008-01-29

More juggling help: "hat" of the day

When I have several working "hats" to wear in a week - teaching, research, etc - a technique that also helps me to keep focused is setting a "hat" for each day, at the start of the week. This way I can do more related tasks in a single day thus reducing context-switching costs.

For example, this week my "hats" are:
Monday -> Teaching
Tuesday -> Big Picture
Wednesday -> PhD
Thursday -> PhD
Friday -> Teaching

2008-01-28

John C. Dvorak on Software License Agreements

Generally speaking, a software license and various terms-of-service and terms-of-use agreements say the following:

  • Whatever you think we said, or whatever we said, about the product may have nothing to do with reality, and you agree not to expect that it does.
  • No matter what happens, including damage to your equipment or even someone's death, you agree not to blame us even if it is our fault.
  • If we are a Web site and you use it, no matter what bad things happen, it is not our fault.
  • If you contribute anything at all to a site or system, we own it.
  • You will never sue us for anything, ever.

My advice is to have a 13-year-old do all the installations and make all the agreements. They cannot legally enter into these contracts. I wish someone would try that trick and litigate it.


John C. Dvorak in PC Magazine

2008-01-18

Juggling tasks at work

No, this post isn't about Circus artists (or is it...? ;-)


Currently I'm struggling with several different nature tasks at the same time. Some are bureaucratic while others are highly focused knowledge work (in my case, programming).

When I'm programming, I'm constantly being interrupted and I lose track of what I'm doing. Bureaucratic tasks are never very complicated, but they require full attention.

If one of the sources of lower productivity (and motivation) is constant interruption, then I tried to eliminate the source of most interruptions, namely, e-mail. I have turned off the email programs while I'm programming and I willed myself into resisting the urge to go and check it every few minutes! Now I work hour-long intervals and things have been working out much better!

It wasn't my idea actually, but my wife's. (One more) big thanks to her!

I'd like to hear how you handle the same problem!

2007-12-05

Extreme programming (XP) distilled

Michael A. Cusumano in "Communications of the ACM", October 2007

Key XP practices:
  • Planning around user stories
  • Small releases of functionality
  • System or project metaphor
  • Simple design
  • Continuous testing (or test-driven design)
  • Refactoring
  • Pair programming
  • Collective product (code)
  • Ownership
  • Continuous integration
  • Minimal overtime
  • On-site customer representative
  • Design (coding) standards

2007-11-26

World Cup Draw / Sorteio do Mundial

After yesterday's World Cup 2010 draw, we have the following qualifying group in Asia (group 3): North Korea, Jordan, Turkmenistan, South Korea.

Maybe the Plan includes cleats...

/ This post is bilingual: English (U.S.) and Portuguese (Portugal) /

Depois do sorteio de ontem para o Mundial de 2010, temos o seguinte grupo de qualificação na Ásia (grupo 3): Coreia do Norte, Jordânia, Turquemenistão e Coreia do Sul.

Talvez o Plano inclua chuteiras...

2007-11-22

On RFID - part 5 (final)

(and last, but not least... In my opinion the best of all the talks I attended at the conference)

Closing session

The speaker of the closing session was Sanjay Sarma from MIT.

He started by presenting a RFID system's functional stack of today, composed of the following layers: tags, readers, middleware, real-time business processes and ERP (Enterprise Resources Planning). Each company has such a system. When it wants to cooperate with a partner company, it uses EPCIS.

Next he discussed what to do when preparing for tomorrow. There are several topics: security, different types of tags, different data acquisition means, new data types, new real-time business processes, new database requirements, new business processes and new exchange mechanisms.

Low-cost RFID is a constant struggle where you can choose, at best, two of the following: cost, range, functionality.

Regarding security, we have requirements for tag authentication, reader authentication and protection from eavesdropping. The latter two require encryption. Cheap and secure tags are, at least, 5 years away, because we need a new class of technologies, like: digital fingerprinting of integrated circuit on tag, read/write fingerprint at manufacturing and verification on demand.

Sensors
need power, so new research is looking for power scavenged from vibrations.

Actuators
will also be possible, i.e. tags that change state (1 bit) on their code. This can be a cheap communication medium for remote control.

Beyond passive RFID
we'll takes to mapping the space with location/identification technologies like: wifi, cellular, wimax - all will live together. We'll have inexpensive radars.
Reading will expand soon, as Application Specific Readers (ASR) emerge, that are cheaper than today's generic-purpose readers, because they take out the stuff you don't need.
Also interesting is the possibility separating the power and signal from the reading process. For instance, a light bulb could power tags and a centralized reader would read the signals.

Concerning health issues, all studies so far have not shown any influence of RFID radiation on pharmaceuticals and other sensitive products.

The RFID system functional stack will have to extended for real-time business processes.
The middleware layer will deal with device management and will be able to detect events: "what", "when" and "where" (literal).
The business process layer the "where" will have to be enriched with additional context, to be meaningful to business and the "why" will also be important, to trigger actions.
The ERP layer will need a new data model, one that takes into account that mistakes are a part of RFID data. Databases will need to be self-healing i.e. correct themselves using basic models of behavior and of the physical world (e.g. "one missing read doesn't mean much in a warehouse stacked with products..."). Databases will also have to act more like streams and less like batches to handle the voluminous data.

RFID will enable new business processes but it's important that the "tail not wag the dog" meaning that business needs should drive RFID and not the other way around...

RFID will enable dynamic, real-time, reactive systems with the ability of just-in-time focus. Discovery will have to accept high-level commands like "Where has this object been?" and "Who damaged it?" with lots of inter company logic. This ability to "touch the physical world" will allow for the invention of new business processes.

In his final remark, Mr. Sarma recommended that "don't paint yourself into a corner" meaning don't limit your future options. As an analogy, he said that we compare the Internet of 2005 with the Internet of today!


Closing speech of the Portuguese Presidency

Bráz Costa from IAPMEI in representation of the Portuguese Minister of Economy and Innovation, talked about the European paradox: good research but bad economic valuation of knowledge. The current Portuguese strategy follows four axis: create knowledge and companies, qualify to manage, grow by innovation and export.

Carlos Zorrinho from the Portuguese Government technological plan urged Portuguese companies to "make excellence a normal state" using their knowledge, technology and innovation, sparked by creativity, with the goal of economic valuation through problem identification and solution building. The goal is a exports-driven economy.

Afterword

This concludes my report on the “On RFID – The next step to the Internet of Things” conference and exhibition that was held at Lisbon, Portugal on the 15th and 16th of November 2007.
I would like to publicly thank the organization for giving me the opportunity to participate in the conference. I would also like to congratulate them on a job well-done!

On RFID - part 4

Day two

Governance of Resources
Bernard Benhamou from the Political Science Institute of Paris presented a "European governance perspective on the ONS". As ONS relies on DNS, the US governance dominance of DNS raises sovereignty issues for other countries. Mr. Benhamou would prefer a multi-lateral, democratic alternative. Mr. Lathia, from the audience, added that the DNS root is comparable to atomic weapons: just having them causes tensions.

Chris Adcock from EPCglobal presented a user-driven perspective to standardization. First he characterized EPCglobal has a neutral, not-for-profit organization with a board of governors composed of 19 individuals representing multiple companies, 9 nationalities (recently including China) and about 100 work groups on standards. The current key challenge of EPCglobal is driving adoption and implementation. EPCglobal's view is that standards govern interfaces, not implementations. EPC standards can be classified in three categories: physical object exchange (air interface protocols), infrastructure (reader protocol, reader management, filtering & collection) and (ALE) and data exchange (enables discovery and sharing of business information, with security authorization, authentication and entitlement mechanisms). The exchange data are EPC events that contain: what, where (location), when (time), why (business process step). ONS is a look-up service and a directory of EPC manager members. Many ONS can coexist as long as they interoperate (entails some redundancy and additional costs). Answering an audience question, he stated that EPCIS doesn't require ONS.

Kiritkumar Lathia from ICT Standards Board and Nokia-Siemens networks presented "Data governance - building trust". In his opinion the fundamental problem is whom to trust in RFID data governance and the common sense solution is that proportionality is needed. The issue is complicated by cultural differences: regional (USA "let the market decide!" vs Europe/Asia "government as caretaker/protector"), generational (young people are less concerned and more willing to use) and conceptual (e.g. privacy in anglo-saxon "My home is my castle" and continental Germany in 1983 "The individual has the right to disclose or not his/her data". In Mr. Lathia's opinion, we standards for simpler, consistent and transparent data manipulation; the disclose policy is a successful approach in applications like Facebook (ex. share this data with everyone/friends/...). As a final note, Mr. Lathia added that all these issues are relevant not just because of RFID, as all information and communication technology means more data sharing and capture issues.

Walter Weigel from ETSI presented a view on "Standards - Europe and beyond". Beyond its success stories - GSM, 3G, DECT, DUB, TETRA - ETSI is expanding its surround services with a center for testing and interoperability and several PlugTests, e.g. 2nd RFID PlugTest in 2008. Mr. Weigel stated emphatically that ETSI is a must consult body, as ESO compliance is required for mentioning technologies in European directives.

Barcode's 30th anniversary
In a short ceremony, a representative of GS1 celebrated the 30th anniversary of the barcode, stating its key features as being simplicity and low-cost. According to estimates, 6% of current product prices is saved by barcodes.

Mobilizing Ideas
Carlos Zorrinho from the Portuguese Government technological plan started the session highlighting the relationship between ideas, economic growth and jobs.

Then Alves Marques introduced the session talking about the importance of lighthouse projects to know where the technology is going and how to materialize the return-on-investment (ROI). In his view, we only really learn by doing.

The first idea was presented by Elena Siri from Instituto Tumori, Milan, Italy and focused on "Blood transfusion". The project's main concerns are patient safety and the auditing of blood transfusion processes. The goals are traceability, monitoring and timely and complete communication. The first results are promising and the project will be extended to hospitals soon.

Markus Kuhn from IML Fraunhofer, Germany, presented "Components labeling for the automotive industry" with the idea of reusing spare parts in new cars. The component's lifecycle would span production, maintenance, disassembly, reconditioning, re-use. Barcodes are not suitable for this application because their resistance is insufficient. The main challenges are: part identification standard for automotive industry; universal database for different OEMs and suppliers; finding suitable tags for the application.

Octávio Lopes from IBERLOG, Portugal, presented HubNet's new logistic concepts. The idea is to make savings in traffic, inventory and delivery time with Hubs - automatic warehouses - where goods can find their way to where they are needed.

Finally, Miguel Ferrinho from Grupo Portucel Soporcel, Portugal, presented WSCOPPI (Wood Supply Chain Optimization of Pulp and Paper Industry) with the goals of automation and optimization to provide traceability from forest to final product with interoperability. A prototype will be developed, for instance, to clarify the different requirements in RFID for tree identification and RFID for wood traceability.


Closing session

(to be continued)

2007-11-21

On RFID - part 3

Parallel sessions - Track 2 - Technology Innovation - Applied innovation

The parallel sessions were divided in 3 tracks: 2 for market drive and 1 for technology innovation. I chose to attend the technology track. The first session from this track was chaired by Fernando Videira from Vodafone and the second was chaired by Luís Magalhães from UMIC.

The first speaker of the session was Anthony Furness from AIM-UK with "RFID a blessing or curse for SMEs?". First, Mr. Furness stated the importance of SMEs (Small and Medium Enterprises - micro < style="font-weight: bold;">Michahelles from ETH Zurich who talked about "Opportunities for fighting counterfeit products". These products span multiple categories - auto-parts, pharmaceutical, aeroplane-parts, luxury goods - and currently account for 2% of international trade (USD 176M). 2/3 are produced in China. The goal of fighting counterfeit is to increase the risk profile of counterfeit players and destroy their business model. RFID technology is promising in this aspect as it gives each item a name and allows it to be tracked through the licit distribution channels. The approaches under study are: unique serial numbering, track-and-trace plausability checks (e.g. same item seen at the same time in two places), smarter tags (e.g. tamper-evident) and reliance on object specific features (e.g. like in Euro bills). Mr. Michahelles mentioned the SToP and BRIDGE projects, funded by the EU, who contribute to this fight. One of the ideas is to empower the end-user to give feedback when spotting counterfeit products. This approach is interesting, but can't be applied for all products, as sometimes consumers are not allies to providers, as they benefit from prestigious products at low prices.

Next was a presentation by Kaj Nummila from VTT about the Indisputable Key project, that deals with tracking in the forest industry: from forest to wood use (excluding paper production). They develop different kinds of tags and readers for different uses (e.g. live tree tagging). At the architecture level, they leverage the GS1 RFID and barcode standards and use a publish-subscribe event bus with papiNET and Stanford messaging technologies.

The following speaker was Alexander Zeier from Hasso Plattner Institute in Germany, who is sponsored by SAP. The talk was about "Integrating RFID data in Enterprise Business Systems". The overall idea is that better quality data can lead to better decisions. RFID enables Real World Awareness (RWA) in business processes: the ability to sense, connect, respond. This can increase automation, improve information and processes, and finally, bring business innovation. Real world examples are: smart supermarket shelves, aircraft preventive maintenance and air-ducts maintenance. However, this also brings a data avalanche e.g. according to estimates, if Walmart used item level tagging then 7 TeraBytes of data would be generated every hour. The new proposed paradigm is management by exception and insight: understanding context through a personalized dashboard; gaining insight through an analysis console; taking action through control console.

The final presentation of the session was made by Jason Burke from SAS, a pharmaceutical company. The title was "Right drug, right dose, right patient". SAS aims to tackle the medical errors problem, as it is estimated to cause more deaths than breast cancer and AIDS. So RFID for e-Pedigree (tracking) ensures the right drug is administered. For risk mitigation strategies, Mr. Bruke presented some recommendations: select appropriate technology to assure privacy; be transparent regarding RFID practices to consumers and patients; allow opt-out choices for personal information; engage consortiums of health providers to follow best practices; educate providers and patients. Finally, regarding governance models, Mr. Burke says they should focus on sensitive information without constraining innovation.


Parallel sessions - Track 2 - Technology Innovation - Future paths for innovation

The first speaker of the session was Klaus Rischmuller from ST Electronics, France. He made an excellent overview presentation of tag electronics: "Developing chips and solutions in a complex environment". The laws dictating tag evolution are: Standards (GS1, ISO), Moore's law (microelectronics), Hertz (antennas can't get much smaller than they are now) and Joule's law (limited computing with very limited energy). Tags can be more than just IDs: they can tell a "story". For this, the initial identity should be stored permanently but there should be code, protocol and data for the "story" part. There are four classes of RFID applications: 1 - simple, cheap labels; 2 - large rewritable memory with security; 3 - battery assisted; 4 - sensor and additional processing.

The next presentation was by Werner John from IZN Fraunhofer, Germany, about "Requirements of common european platform for complex RFID applications". He presented a RFID case-study at Deutsche Post. The main idea is of tags having a display with a visual representation of their internal state, readable by humans. This display is very interesting for system migration, evolution and as a fallback procedures when electronic reading is not possible. At the end of his presentation, Mr. John stressed the need for a RFID engineer certification, i.e. people with the right skills mix to develop and implement RFID-based systems.

The next presentation was by Gerd Wolfram from CERP (and from Metro Group). The title was a "Future roadmap for research projects". Mr. Wolfram presented CERP's RFID reference model that structures and describes the different RFID application areas. It is CERP's view that the application determines the technology. So within each application field, CERP work groups performed: state-of-the-art survey, vision statement, gap analysis and identified research needs. The results are 20 major research needs classified in three categories: urgent (1-3 years), mid-term (3-5 years) and long-term (> 5 years). CERP's RFID reference model is a good starting point for any RFID solutions overview and is freely accessible at their web site.

The final presentation was by Ovidiu Vermesan from SINTEF in Norway. The title was "Smart systems on tags" and presented a technology roadmap towards ubiquitous systems: from simple but extensible protocols to more complex protocols. He presented Intellisense RFID, a project that aims to abstract tag type and reader type using multi-frequency antennas, to overcome the current fragmentation of RFID technologies and to achieve unified systems. Tags have a "personality": they sense, actuate, identify, interact, interface and communicate. Their technical features are: small size, ultra low power, low cost, invisible, and autonomous. The approaches to the overall system can be: centralized (EPC-like), decentralized (smart-tag-centered) or something in between, to achieve a more efficient network infrastructure. Finally, Mr. Vermesan presented a very thorough challenges list: environment independent tags (metal, liquids); smart tag networking (tag-2-tag); advanced power supplies (fuel cells, polymer batteries); real-time localization and tracking; data security (energy efficient encryption technology); higher frequencies (enhanced positioning resolution, smaller antennas, compact mobile readers); low power, large capacity memories; communication protocols technologies (low power, bandwidth efficiency); printable electronics (polymer electronics). In the questions and answers, Mr. Vermesan mentioned his opinion that the mobile phone with integrated reader can be an entry point from the ad-hoc network into the wireless network. One final note: this presentation had very good figures, that elegantly conveyed the ideas.


Day two

(to be continued)

On RFID - part 2

Security and privacy: Does Europe need new rules for RFID?

This session had two initial presentations and a panel discussion.

Kathryn Ratté from the US Federal Trade Commission (FTC) was invited to make a presentation of the US approach to security and privacy in RFID, as the FTC is responsible for consumer protection and law enforcement in the private uses of data. They have an internal RFID group since June 2004. They try to prevent consumer harm by helping consumers help themselves through information and education, but also make sure businesses keep their promises to customers and support industry self-regulation initiatives to create meaningful accountability mechanisms. They recognize there isn't a single solution suitable for all cases, so they do a company assessment and risk analysis for each case.

Reinhard Posch from the ENISA (European Network and Information Security Agency) presented his view on the subject. He identified security, supply chain and asset tracking as the main RFID applications. He regards tag cloning as the main security threat for RFID applications and mentioned signature-generating tags as a possible solution. Other technical challenges for RFID are system scalability (billions of tags) and the management of access rights to data. He also briefly mentioned other challenges for RFID: environmental and health issues.

Next started the panel discussion moderated by the journalist Vasco Trigo. The participants were David Hoffman from Intel, Peter Hustinx from EDPS, Michael Donohue from OECD, Emilie Barrau from BEUC, Kathryn Ratté from the US FTC and Reinhard Posch from ENISA.

After attending the hour-long discussion, my notes are the following:
  • Surveys show that consumers have privacy and security concerns. Privacy trade-offs for consumers require information, but we have to find a clear way to state the issues. Opting out of RFID won't be a real option in many cases, as some applications will be mandatory (e.g. passport) and others won't have alternatives;
  • Privacy doesn't mean the same accross the world, but there are some shared principles;
  • Another inconvenient truth (reference to Al Gore's global warming alert movie) is that RFID is the infrastructure for worldwide surveillance;
  • However, RFID is a suite of technologies and not all of them affect privacy. At this moment, it is important to avoid creating generic rules that can hinder potentially useful applications (e.g. upfront consent vs unconscious patient in hospital);
  • Change is unavoidable in 5 year time frame. Technology misuse will happen but it won't stop technology adoption. We need reasonable solutions proportional to risk, so we need to make privacy impact assessment and to leverage PET (privacy enhancing technologies);
  • People would prefer to build the security in the technology from start, but this isn't completely possible because not all problems can be anticipated;
  • Regulation can act now to require minimum tag capabities, like tag kill. Only later will the problems be truly assessed and then the existing mechanisms can be used to implement solutions;
  • The main distinguishing feature of RFID compared to existing technologies is the invisibility of tags and the possibility of covert reading. This is what might make current legislation obsolete.
Parallel sessions - track 2 - Technology innovation - applied innovation

(to be continued)