Skip to main navigation Skip to search Skip to main content

Quasi-linear cryptanalysis of a secure RFID ultralightweight authentication protocol

  • Pedro Peris-Lopez
  • , Julio Cesar Hernandez-Castro
  • , Raphael C.W. Phan
  • , Juan M.E. Tapiador
  • , Tieyan Li

Research output: Chapter in Book/Report/Conference proceedingConference PaperResearchpeer-review

Abstract

In 2010, Yeh, Lo and Winata [1] proposed a process-oriented ultralightweight RFID authentication protocol. This protocol is claimed to provide strong security and robust privacy protection, while at the same time the usage of resources on tags is optimized. Nevertheless, in this paper we show how the protocol does not achieve any of its intended security objectives; the main result is that the most valuable information stored on the tag, that is, the static identifier ID, is easily recovered even by a completely passive attacker in a number of ways. More precisely, we start by presenting a traceability attack on the protocol that allows tags to be traced. This essentially exploits the fact that the protocol messages leak out at least one bit of the static identifier. We then present a passive attack (named Norwegian attack) that discloses ⌊ log2 L ⌋ bits of the ID, after observing roughly O(L) authentication sessions. Although this attack may seem less feasible in retrieving the full 96-bits of the ID due to the large number of eavesdropped sessions involved, it is already powerful enough to serve as a basis for a very effective traceability attack. Finally, our last attack represents a step forward in the use of a recent cryptanalysis technique (called Tango attack [2]), which allows for an extremely efficient full disclosure attack, capable of revealing the value of the whole ID after eavesdropping only a very small number of sessions.

Original languageEnglish
Title of host publicationInformation Security and Cryptology - 6th International Conference, Inscrypt 2010, Revised Selected Papers
Pages427-442
Number of pages16
DOIs
Publication statusPublished - 2011
Externally publishedYes
EventInternational Conference on Information Security and Cryptology (Inscript) 2010 - Shanghai China, Shanghai, China
Duration: 20 Oct 201024 Oct 2010
Conference number: 6th
http://www.inscrypt.cn/2010/
https://link.springer.com/book/10.1007/978-3-642-21518-6 (Proceedings)

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume6584 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

ConferenceInternational Conference on Information Security and Cryptology (Inscript) 2010
Abbreviated titleInscrypt 2010
Country/TerritoryChina
CityShanghai
Period20/10/1024/10/10
OtherThe 6th China International Conference on Information Security and Cryptology (Inscrypt 2010)
Internet address

Keywords

  • Authentication
  • Cryptanalysis
  • RFID
  • Ultralightweight

Cite this