EAGER: Collaborative Research: Towards Context-Aware Security and Privacy for RFID Systems
EAGER: Collaborative Research: Towards Context-Aware Security and Privacy for RFID Systems
批准号:
1153573
负责人:
Di Ma
金额:
$11.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2011
资助国家:
美国
项目状态:
已结题
起止时间:
2011-10-01 至 2014-09-30
中文摘要
尽管RFID系统的部署越来越普遍,但它仍然受到各种安全和隐私威胁的困扰。大量的这些威胁是由标签引起的?对任何读者请求的杂乱响应。这使得敏感的标签信息很容易受到未经授权的读取。它还引发了不同形式的中继攻击,通过在合法标签和阅读器之间传递信息,串通对可以成功地冒充合法标签,而无需实际拥有它。本研究通过利用新装备的下一代(被动)RFID标签的传感能力,探索了新的上下文感知安全和隐私机制。目标是提供改进的保护,防止未经授权的读取和中继攻击,同时不破坏RFID系统提供的可用性和效率。该项目还包括在经济和功率限制方面对拟议机制进行可行性研究,并对可能的(新)以传感器为中心的攻击进行系统分析。总的建议活动范围从系统设计和分析到实现和性能度量。更广泛地说,这项探索性工作旨在更好地理解利用来自物理世界的参数来解决网络系统的安全和隐私问题的可行性。在教育活动方面,将开发以资源受限设备和轻量级加密工具为重点的新安全课程。
英文摘要
Despite their increasingly ubiquitous deployment, RFID systems are plagued with a wide variety of security and privacy threats. A large number of these threats arise due to the tag?s promiscuous response to any reader requests. This renders sensitive tag information easily subject to unauthorized reading. It also incites different forms of relay attacks whereby a colluding pair, by relaying information between a legitimate tag and reader, can successfully impersonate the legitimate tag without actually possessing it.This research explores novel context-aware security and privacy mechanisms by leveraging the newly-equipped sensing capabilities on the next generation (passive) RFID tags. The goal is to provide improved protection against unauthorized reading and relay attacks without undermining the usability and efficiency offered by the RFID systems. The project also includes a feasibility study of the proposed mechanisms in terms of both economical and power constraints, and a systematic analysis of possible (new) sensor-centric attacks. The overall proposed activities range from system design and analysis to implementation and performance measurements. More broadly, this exploratory work intends to arrive at a better understanding of the feasibility of utilizing parameters derived from the physical world to solve security and privacy issues of the cyber systems. In terms of educational activities, new security courses focusing on resource-constrained devices and lightweight cryptographic tools will be developed.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
EDU: Collaborative: Enhancing Pervasive and Mobile Computing Security Education With Research Integration
-
批准号:1419280
-
项目类别:Standard Grant
-
资助金额:$20.51万
-
财政年份:2014
-
负责人:Di Ma
-
依托单位:
I-Corps: Commercialization Study of Context-aware Security and Privacy Techniques for RFID Applications
-
批准号:1342107
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2013
-
负责人:Di Ma
-
依托单位:
海外基金