A Vulnerability in the Song Authentication Protocol for Low-Cost RFID Tags

被引:0
|
作者
Abughazalah, Sarah [1 ]
Markantonakis, Konstantinos [1 ]
Mayes, Keith [1 ]
机构
[1] Univ London, Smart Card Ctr Informat Secur Grp SCC ISG, Egham TW20 0EX, Surrey, England
关键词
RFID; mutual authentication; protocol; security; privacy;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we describe a vulnerability against one of the most efficient authentication protocols for low-cost RFID tags proposed by Song. The protocol defines a weak attacker as an intruder which can manipulate the communication between a reader and tag without accessing the internal data of a tag. It has been claimed that the Song protocol is able to resist weak attacks, such as denial of service (DoS) attack; however, we found that a weak attacker is able to desynchronise a tag, which is one kind of DoS attack. Moreover, the database in the Song protocol must use a brute force search to retrieve the tag's records affecting the operational performance of the server. Finally, we propose an improved protocol which can prevent the security problems in Song protocol and enhance the server's scalability performance.
引用
收藏
页码:102 / 110
页数:9
相关论文
共 50 条
  • [21] Employing Lightweight Primitives on Low-cost RFID Tags for Authentication
    Li, Tieyan
    [J]. 68TH IEEE VEHICULAR TECHNOLOGY CONFERENCE, FALL 2008, 2008, : 1357 - 1361
  • [22] Cryptanalysis of the LMAP Protocol: A Low-cost RFID Authentication Protocol
    Li, Jing
    Zhou, Zhiping
    Wang, Ping
    [J]. 2017 29TH CHINESE CONTROL AND DECISION CONFERENCE (CCDC), 2017, : 7292 - 7297
  • [23] A Mutual Authentication Protocol for Low-Cost RFID Tags Formally Verified Using CasperFDR and AVISPA
    Abughazalah, Sarah
    Markantonakis, Kostantinos
    Mayes, Keith
    [J]. 2013 8TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2013, : 44 - 51
  • [24] Spacing based Authentication Protocol for Low-Cost RFID
    Jin, Zhen-Ai
    Cheng, Zi-Qiang
    Yoo, Kee-Young
    [J]. FGCN: PROCEEDINGS OF THE 2008 SECOND INTERNATIONAL CONFERENCE ON FUTURE GENERATION COMMUNICATION AND NETWORKING, VOLS 1 AND 2, 2008, : 158 - +
  • [25] Security and privacy on authentication protocol for low-cost RFID
    Li, Yong-Zhen
    Cho, Young-Bok
    Um, Nam-Kyoung
    Lee, Sang-Ho
    [J]. COMPUTATIONAL INTELLIGENCE AND SECURITY, 2007, 4456 : 788 - +
  • [26] An efficient authentication protocol for low-cost RFID systems
    Jin, Zhen-Ai
    Cho, Hyun-Ju
    Yoo, Kee-Young
    [J]. AGENT AND MULTI-AGENT SYSTEMS: TECHNOLOGIES AND APPLICATIONS, PROCEEDINGS, 2007, 4496 : 999 - +
  • [27] Security and privacy on authentication protocol for low-cost RFID
    Li, Yong-Zhen
    Cho, Young-Bok
    Um, Nam-Kyoung
    Lee, Sang-Ho
    [J]. 2006 INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY, PTS 1 AND 2, PROCEEDINGS, 2006, : 1101 - 1104
  • [28] A New Ultralightweight RFID Protocol for Low-Cost Tags: RAP
    Zhuang, Xu
    Zhu, Yan
    Chang, Chin-Chen
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2014, 79 (03) : 1787 - 1802
  • [29] SAMA: Serverless Anonymous Mutual Authentication for Low-Cost RFID Tags
    Myneni, Sowmya
    Misra, Satyajayant
    Xue, Guoliang
    [J]. 2011 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2011,
  • [30] Ultra-Lightweight Mutual Authentication Protocol to Prevent Replay Attacks for Low-Cost RFID Tags
    Abd Alhasan, Ahmed Qasim
    Rohani, Mohd Foad
    Abu-Ali, Mohammed Sabri
    [J]. IEEE ACCESS, 2024, 12 : 50925 - 50934