Security Analysis of Ultra-lightweight Cryptographic Protocol for Low-cost RFID Tags: Gossamer Protocol

被引:33
|
作者
Bilal, Zeeshan [1 ]
Masood, Ashraf [1 ]
Kausar, Firdous [1 ]
机构
[1] NUST, Coll Signals, Rawalpindi, Pakistan
关键词
Synchronized; Mutual Authentication; Ultra-lightweight Cryptography; Ubiquitous Computing; SASI;
D O I
10.1109/NBiS.2009.9
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Gossamer protocol has been recently published to achieve mutual authentication in low-cost RFID tags. This protocol is considered to fall in ultra-lightweight class as it incorporates simple and low cost operations. Most of the earlier proposals in this class were exposed soon after their publication. Common weaknesses included use of Triangular functions and improper use of logic operators. Gossamer protocol used two non-triangular functions a) ROTbits and b) MIXbits. These functions provide confusion and diffusion properties and are implemented as cheaper operations. Thus, this protocol can be used for EPCglobal Class-1 Generation-2 standard (considered as universal standard for low-cost tags). This protocol is able to overcome existing weaknesses and is considered to be more attractive for low-capability devices as compared to earlier protocols of this class. In this paper, we analyze the security features provided by Gossamer protocol. The vulnerabilities discovered during this analysis reveal that different attacks including denial of service, memory and computation exhaustive, de-synchronization, replay, attack on data integrity and IDS (index pseudonym) collision are possible. As a consequence, we propose a new mutual authentication protocol keeping in mind the constraints and making use of the existing operations without addition of any expensive one. The analysis of the proposed protocol shows that it is resistant to all the attacks possible in case of Gossamer protocol. A comparative security analysis shows that proposed protocol provides better security features with a small compromise of communication overheads. Two additional public messages are exchanged between the reader and the tag to address the vulnerabilities present in Gossamer protocol.
引用
收藏
页码:260 / 267
页数:8
相关论文
共 50 条
  • [1] Security Analysis of Ultra-lightweight Protocol for Low-Cost RFID Tags: SSL-MAP
    Kianersi, Mehrdad
    Gardeshi, Mahmoud
    Yousefi, Hamed
    [J]. RECENT TRENDS IN WIRELESS AND MOBILE NETWORKS, 2011, 162 : 236 - 245
  • [2] An Ultra-Lightweight Secure RFID Authentication Protocol for Low-Cost Tags
    Kumar, Sanjeev
    Banka, Haider
    Kaushik, Baijnath
    Sharma, Surbhi
    [J]. JOURNAL OF COMPUTER VIROLOGY AND HACKING TECHNIQUES, 2024,
  • [3] Pitfalls in an Ultra-lightweight Authentication Protocol for Low-cost RFID
    Chen, Chien-Ming
    Pan, Jeng-Shyang
    Tso, Raylin
    Huang, Szu-Wei
    Wu, Mu-En
    [J]. 2014 TENTH INTERNATIONAL CONFERENCE ON INTELLIGENT INFORMATION HIDING AND MULTIMEDIA SIGNAL PROCESSING (IIH-MSP 2014), 2014, : 634 - 637
  • [4] Ultra-Lightweight Mutual Authentication Protocol to Prevent Replay Attacks for Low-Cost RFID Tags
    Abd Alhasan, Ahmed Qasim
    Rohani, Mohd Foad
    Abu-Ali, Mohammed Sabri
    [J]. IEEE ACCESS, 2024, 12 : 50925 - 50934
  • [5] Advances in Ultralightweight Cryptography for Low-Cost RFID Tags: Gossamer Protocol
    Peris-Lopez, Pedro
    Hernandez-Castro, Julio Cesar
    Tapiador, Juan M. E.
    Ribagorda, Arturo
    [J]. INFORMATION SECURITY APPLICATIONS, 2009, 5379 : 56 - 68
  • [6] On the security of a new ultra-lightweight authentication protocol in IoT environment for RFID tags
    Wang, King-Hang
    Chen, Chien-Ming
    Fang, Weicheng
    Wu, Tsu-Yang
    [J]. JOURNAL OF SUPERCOMPUTING, 2018, 74 (01): : 65 - 70
  • [7] On the security of a new ultra-lightweight authentication protocol in IoT environment for RFID tags
    King-Hang Wang
    Chien-Ming Chen
    Weicheng Fang
    Tsu-Yang Wu
    [J]. The Journal of Supercomputing, 2018, 74 : 65 - 70
  • [8] The security and improvement of an ultra-lightweight RFID authentication protocol
    Li, Tieyan
    Deng, Robert H.
    Wang, Guilin
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2008, 1 (02) : 135 - 146
  • [10] ESRAS: An efficient and secure ultra-lightweight RFID authentication scheme for low-cost tags
    Shariq, Mohd
    Singh, Karan
    Lal, Chhagan
    Conti, Mauro
    Khan, Tayyab
    [J]. COMPUTER NETWORKS, 2022, 217