On the security of Lo et al.s ownership transfer protocol

Masoumeh Safkhani and Nasour Bagheri and Majid Naderi and Ali Mahani

Abstract: Recently Lo et al. have proposed an ownership transfer pro- tocol for RFID objects using lightweight computing operators and claim their protocol provides stronger security robustness and higher perfor- mance efficiency in comparison with existing solutions. However, in this paper we show that their claim unfortunately does not hold. More pre- cisely, we present tags secret disclosure attack, new owners secret disclo- sure and fraud attack against the Lo et al.s ownership transfer protocol. The success probability of all attacks is 1 while the complexity is only one run of protocol. Our observation shows that this protocol compro- mise the privacy of the tag and the new owner.

Category / Keywords: RFID, Ownership Transfer Protocol, Disclosure Attack, Fraud Attack.

Date: received 15 Jan 2012, last revised 17 Feb 2012

