首页 | 本学科首页   官方微博 | 高级检索  
     


Cryptanalysis of an EPC Class-1 Generation-2 standard compliant authentication protocol
Authors:Pedro Peris-Lopez  Julio C Hernandez-Castro
Affiliation:a Delft University of Technology (TU-Delft), Faculty of Electrical Engineering, Mathematics, and Computer Science (EEMCS), Information Security and Privacy Lab, P.O. Box 5031 2600 GA, Delft, The Netherlands
b School of Computing, Buckingham Building, Lion Terrace, Portsmouth PO1 3HE, United Kingdom
c Department of Computer Science, University of York, Heslington, York, YO10 5DD, United Kingdom
Abstract:Recently, Chen and Deng (2009) proposed an interesting new mutual authentication protocol. Their scheme is based on a cyclic redundancy code (CRC) and a pseudo-random number generator in accordance with the EPC Class-1 Generation-2 specification. The authors claimed that the proposed protocol is secure against all classical attacks against RFID systems, and that it has better security and performance than its predecessors. However, in this paper we show that the protocol fails short of its security objectives, and in fact offers the same security level than the EPC standard it tried to correct. An attacker, following our suggested approach, will be able to impersonate readers and tags. Untraceability is also not guaranteed, since it is easy to link a tag to its future broadcast responses with a very high probability. Furthermore, readers are vulnerable to denial of service attacks (DoS), by obtaining an incorrect EPC identifier after a successful authentication of the tag. Moreover, from the implementation point of view, the length of the variables is not compatible with those proposed in the standard, thus further discouraging the wide deployment of the analyzed protocol. Finally, we propose a new EPC-friendly protocol, named Azumi, which may be considered a significant step toward the security of Gen-2 compliant tags.
Keywords:RFID  EPC  Security  Authentication  Cryptanalysis
本文献已被 ScienceDirect 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号