On the security of Lo et al.’s ownership transfer protocol

Masoumeh Safkhani and Nasour Bagheri and Majid Naderi and Ali Mahani

Abstract: Recently Lo et al. have proposed an ownership transfer pro- tocol for RFID objects using lightweight computing operators and claim their protocol provides stronger security robustness and higher perfor- mance efficiency in comparison with existing solutions. However, in this paper we show that their claim unfortunately does not hold. More pre- cisely, we present tag’s secret disclosure attack, new owner’s secret disclo- sure and fraud attack against the Lo et al.’s ownership transfer protocol. The success probability of all attacks is “1” while the complexity is only one run of protocol. Our observation shows that this protocol compro- mise the privacy of the tag and the new owner.

Category / Keywords: RFID, Ownership Transfer Protocol, Disclosure Attack, Fraud Attack.

