SecLAP: Secure and lightweight RFID authentication protocol for Medical IoT

被引:70
|
作者
Aghili, Seyed Farhad [1 ]
Mala, Hamid [1 ]
Kaliyar, Pallavi [2 ]
Conti, Mauro [2 ]
机构
[1] Univ Isfahan, Fac Comp Engn, Dept Informat Technol Engn, Hezar Jerib St, Esfahan 8174673441, Iran
[2] Univ Padua, Dept Math, Padua, Italy
关键词
RFID; Internet of Things; FPGA; Secret disclosure attack; Impersonation attack; Anonymity;
D O I
10.1016/j.future.2019.07.004
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The safety of medical data and equipment plays a vital role in today's world of Medical Internet of Things (MIoT). These IoT devices have many constraints (e.g., memory size, processing capacity, and power consumption) that make it challenging to use cost-effective and energy-efficient security solutions. Recently, researchers have proposed a few Radio-Frequency Identification (RFID) based security solutions for MIoT. The use of RFID technology in securing IoT systems is rapidly increasing because it provides secure and lightweight safety mechanisms for these systems. More recently, authors have proposed a lightweight RFID mutual authentication (LRMI) protocol. The authors argue that LRMI meets the necessary security requirements for RFID systems, and the same applies to MIoT applications as well. In this paper, our contribution has two-folds, firstly we analyze the LRMI protocols security to demonstrate that it is vulnerable to various attacks such as secret disclosure, reader impersonation, and tag traceability. Also, it is not able to preserve the anonymity of the tag and the reader. Secondly, we propose a new secure and lightweight mutual RFID authentication (SecLAP) protocol, which provides secure communication and preserves privacy in MIoT systems. Our security analysis shows that the SecLAP protocol is robust against de-synchronization, replay, reader/tag impersonation, and traceability attacks, and it ensures forward and backward data communication security. We use Burrows-Abadi-Needham (BAN) logic to validate the security features of SecLAP. Moreover, we compare SecLAP with the state-of-the-art and validate its performance through a Field Programmable Gate Array (FPGA) implementation, which shows that it is lightweight, consumes fewer resources on tags concerning computation functions, and requires less number of flows. (C) 2019 Elsevier B.V. All rights reserved.
引用
收藏
页码:621 / 634
页数:14
相关论文
共 50 条
  • [1] A Secure and Lightweight Authentication Protocol for RFID
    Liu Cheng
    Lin Shenwen
    Li Yingbo
    Li Na
    Wang Xuren
    [J]. PROCEEDINGS OF 2015 IEEE 5TH INTERNATIONAL CONFERENCE ON ELECTRONICS INFORMATION AND EMERGENCY COMMUNICATION, 2015, : 317 - 320
  • [2] Cloud-based lightweight secure RFID mutual authentication protocol in IoT
    Fan, Kai
    Luo, Qi
    Zhang, Kuan
    Yang, Yintang
    [J]. INFORMATION SCIENCES, 2020, 527 : 329 - 340
  • [3] Secure and Lightweight Authentication Protocol for Mobile RFID Privacy
    Lee, Hyeong-Chan
    Eom, TaeYang
    Yi, Jeong Hyun
    [J]. APPLIED MATHEMATICS & INFORMATION SCIENCES, 2013, 7 (01): : 421 - 426
  • [4] A Secure, Lightweight, and Anonymous User Authentication Protocol for IoT Environments
    Son, Seunghwan
    Park, Yohan
    Park, Youngho
    [J]. SUSTAINABILITY, 2021, 13 (16)
  • [5] Lightweight RFID Protocol for Medical Privacy Protection in IoT
    Fan, Kai
    Jiang, Wei
    Li, Hui
    Yang, Yintang
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2018, 14 (04) : 1656 - 1665
  • [6] Verifying a secure authentication protocol for IoT medical devices
    Bae, Woo-Sik
    [J]. CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2019, 22 (Suppl 1): : 1985 - 1990
  • [7] Verifying a secure authentication protocol for IoT medical devices
    Woo-Sik Bae
    [J]. Cluster Computing, 2019, 22 : 1985 - 1990
  • [8] On a Lightweight Authentication Protocol for RFID
    Nastase, George-Daniel
    Tiplea, Ferucio Laurentiu
    [J]. INNOVATIVE SECURITY SOLUTIONS FOR INFORMATION TECHNOLOGY AND COMMUNICATIONS, 2015, 9522 : 212 - 225
  • [9] LRMAPC: a lightweight RFID mutual authentication protocol with cache in the reader for IoT
    Fan, Kai
    Liang, Chen
    Li, Hui
    Yang, Yintang
    [J]. 2014 IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION TECHNOLOGY (CIT), 2014, : 276 - 280
  • [10] A Secure and Lightweight Authentication Protocol for IoT-Based Smart Homes
    Oh, JiHyeon
    Yu, SungJin
    Lee, JoonYoung
    Son, SeungHwan
    Kim, MyeongHyun
    Park, YoungHo
    [J]. SENSORS, 2021, 21 (04) : 1 - 24