On Ultralightweight RFID Authentication Protocols

On Ultralightweight RFID Authentication Protocols
复制标题

DOI:
10.1109/tdsc.2010.75
复制
发表时间:
2011-07-01
影响因子:
7.3
通讯作者:
De Santis, Alfredo
De Santis, Alfredo
中科院分区:
计算机科学2区
文献类型:
--
作者:
D'Arco, Paolo;De Santis, Alfredo

文献摘要

被引文献

相似文献

最近的一个研究趋势,由RFID技术的大规模部署的动机,着眼于加密协议,用于保护实体之间的通信,其中一些方具有非常有限的计算能力。在本文中,我们专注于SASI,一个新的RFID认证协议,旨在提供强认证和强完整性。SASI是RFID认证协议家族的一个很好的代表,被称为超轻量RFID认证协议。这些协议适用于具有有限计算能力和存储的被动标签,涉及简单的逐位操作,例如与、或、异或、模加法和循环移位操作。它们是高效的,符合硬件的限制,可以被看作是上述研究趋势的一个例子。但是,主要关注的是这些协议的真实的安全性,这些协议往往只得到表面上合理和直观的论证的支持。我们提供这项工作的贡献如下:我们首先显示SASI协议中的一些弱点,然后,我们描述了如何通过一系列简单的步骤,这些弱点可以用来计算在一个有效的方式用于认证过程中使用的所有秘密数据。具体来说,我们描述了三种攻击:1)去同步化攻击,通过它,对手可以打破RFID阅读器和标签之间的同步; 2)身份泄露攻击,通过它,对手可以计算标签的身份;和3)完全泄露攻击,它使对手能够检索存储在标签中的所有秘密数据。然后,我们提出了一些实验结果,通过运行几个测试的协议的实现,以评估所提出的攻击,这证实了攻击是有效的和高效的性能。结果表明,一个活跃的对手通过与标签进行大约300次的交互,使得认证协议完全无用。最后,我们用一些观察来结束本文。SASI的密码分析对超轻量化方法有了一些新的认识,也可以作为对该领域研究人员的警告,并试图应用这些技术。事实上,这项工作的结果,提出了严重的问题,关于超轻型家庭的协议的限制,以及这些特设协议设计策略和非正式的安全分析的好处。
A recent research trend, motivated by the massive deployment of RFID technology, looks at cryptographic protocols for securing communication between entities in which some of the parties have very limited computing capabilities. In this paper, we focus our attention on SASI, a new RFID authentication protocol, designed for providing Strong Authentication and Strong Integrity. SASI is a good representative of a family of RFID authentication protocols, referred to as Ultralightweight RFID authentication protocols. These protocols, suitable for passive Tags with limited computational power and storage, involve simple bitwise operations such as and, or, exclusive or, modular addition, and cyclic shift operations. They are efficient, fit the hardware constraints, and can be seen as an example of the above research trend. However, the main concern is the real security of these protocols, which are often supported only by apparently reasonable and intuitive arguments. The contribution we provide with this work is the following: we start by showing some weaknesses in the SASI protocol, and then, we describe how such weaknesses, through a sequence of simple steps, can be used to compute in an efficient way all secret data used for the authentication process. Specifically, we describe three attacks: 1) a desynchronization attack, through which an adversary can break the synchronization between the RFID Reader and the Tag; 2) an identity disclosure attack, through which an adversary can compute the identity of the Tag; and 3) a full disclosure attack, which enables an adversary to retrieve all secret data stored in the Tag. Then, we present some experimental results, obtained by running several tests on an implementation of the protocol, in order to evaluate the performance of the proposed attacks, which confirm that the attacks are effective and efficient. It comes out that an active adversary by interacting with a Tag more or less three hundred times, makes the authentication protocol completely useless. Finally, we close the paper with some observations. The cryptoanalysis of SASI gets some new light on the ultralightweight approach, and can also serve as a warning to researchers working on the field and tempted to apply these techniques. Indeed, the results of this work, rise serious questions regarding the limits of the ultralightweight family of protocols, and on the benefits of these ad hoc protocol design strategies and informal security analysis.