Cryptanalysis of a Hash Based Mutual RFID Tag Authentication Protocol

Cryptanalysis of a Hash Based Mutual RFID Tag Authentication Protocol
复制标题

DOI:
10.1007/s11277-016-3513-4
复制
发表时间:
2016-12-01
影响因子:
2.2
通讯作者:
Zhong, Ji-Dong
Zhong, Ji-Dong
中科院分区:
计算机科学4区
文献类型:
--
作者:
Sun, Da-Zhi;Zhong, Ji-Dong

文献摘要

被引文献

相似文献

Srivastava 等人最近提出了一种基于哈希的双向 RFID 认证协议。他们声称该协议可以提供几个有吸引力的安全特性,即相互认证以及抵御窃听和跟踪攻击、重放攻击、中间人攻击和去同步。然而,我们发现该协议容易受到论文中提出的新型伪造攻击的影响。伪造攻击破坏了协议的相互认证以及对中间人攻击和去同步的抵抗力。除了安全漏洞之外,该协议的实现效率也很低,因为它同时使用了时间戳和随机数。因此,该协议不适合无线安全系统。我们希望我们的密码分析结果有助于为未来的无线安全系统设计更强大的 RFID 身份验证协议。
Srivastava et al., recently proposed a hash based mutual RFID authentication protocol. They claimed that the protocol can provide several attractive security features, i.e., the mutual authentication and the resistance against the eavesdropping and tracing attack, the replay attack, the man-in-the-middle attack, and the desynchronization. However, we find that the protocol is vulnerable to a novel forgery attack presented in the paper. The forgery attack undermines the protocol in the mutual authentication and the resistance against both the man-in-the-middle attack and the desynchronization as claimed. In addition to the security vulnerability, the protocol is also inefficient in implementation, because it makes use of the timestamp and random number simultaneously. Therefore, the protocol is not suitable for the wireless security systems. We hope that our cryptanalysis results are useful to design more robust RFID authentication protocols for the wireless security systems in the future.