Cryptology ePrint Archive: Report 2015/980

Analysis of an RFID Authentication Protocol in Accordance with EPC Standards

Behzad Abdolmaleki, Hamidreza Bakhshi, Karim Baghery, Mohammad Reza Aref

Abstract: In the past few years, the design of RFID authentication protocols in accordance with the EPC Class-1 Generation-2 (EPC C1 G2) standards, has been one of the most important challenges in the information security domain. Although RFID systems provide user-friendly services for end-users, they can make security and privacy concerns for them. In this paper we analyze the security of an RFID mutual authentication protocol which is based on EPC Class-1 Generation-2 standard and proposed in 2013. The designers of protocol claimed that their protocol is secure against different security attacks and provides user privacy. In this paper, we show that unlike their claims, their protocol is not secure against most of the security attacks such as replay attack, the tag’s ID exposure, and the spoofing attacks. As a result, their protocol cannot provide security of RFID users in different authentication applications. Finally, in order to prevent the aforementioned attacks and overcome all the existing weaknesses, we apply a modification in the updating procedure of the protocol and propose a strengthened version of it.

Category / Keywords: cryptographic protocols / Security and Privacy, RFID, Authentication protocols

Original Publication (in the same form): International Journal of Information & Communication Technology Research

Date: received 10 Oct 2015

Contact author: abdolmaleki behzad at yahoo com

Available format(s): PDF | BibTeX Citation

Version: 20151012:210414 (All versions of this report)

Short URL: ia.cr/2015/980

Discussion forum: Show discussion | Start new discussion


[ Cryptology ePrint archive ]