Attacks on ownership transfer scheme for multi-tag multi-owner passive RFID environments.

Saved in:
Bibliographic Details
Title: Attacks on ownership transfer scheme for multi-tag multi-owner passive RFID environments.
Authors: Munilla, J.1 munilla@ic.uma.es, Burmester, M.2, Peinado, A.1
Source: Computer Communications. Aug2016, Vol. 88, p84-88. 5p.
Subjects: Radio frequency identification systems, Computer network protocols, Computer security, Security management, Data privacy
Abstract: Sundaresan et al. proposed recently a novel ownership transfer protocol for multi-tag multi-owner RFID environments that complies with the EPC Class1 Generation2 standard. The authors claim that this provides individual-owner privacy and prevents tracking attacks. We show that this protocol falls short of its security objectives, and describe attacks that allow: ( a ) an eavesdropper to trace a tag, ( b ) the previous owner to obtain the private information that the tag shares with the new owner, and ( c ) an adversary that has access to the data stored on a tag to link this tag to previous interrogations (violating forward-secrecy). We analyze the security proof and show that while the first two cases can be addressed with a more careful design, strong privacy remains an open problem for lightweight RFID applications. [ABSTRACT FROM AUTHOR]
Copyright of Computer Communications is the property of Elsevier B.V. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
Description
Abstract:Sundaresan et al. proposed recently a novel ownership transfer protocol for multi-tag multi-owner RFID environments that complies with the EPC Class1 Generation2 standard. The authors claim that this provides individual-owner privacy and prevents tracking attacks. We show that this protocol falls short of its security objectives, and describe attacks that allow: ( a ) an eavesdropper to trace a tag, ( b ) the previous owner to obtain the private information that the tag shares with the new owner, and ( c ) an adversary that has access to the data stored on a tag to link this tag to previous interrogations (violating forward-secrecy). We analyze the security proof and show that while the first two cases can be addressed with a more careful design, strong privacy remains an open problem for lightweight RFID applications. [ABSTRACT FROM AUTHOR]
ISSN:01403664
DOI:10.1016/j.comcom.2016.05.007