Paper 2016/387

Game-Based Cryptanalysis of a Lightweight CRC-Based Authentication Protocol for EPC Tags

K. Baghery, B. Abdolmaleki, and M. J. Emadi

Abstract

The term "Internet of Things (IoT)" expresses a huge network of smart and connected objects which can interact with other devices without our interposition. Radio frequency identification (RFID) is a great technology and an interesting candidate to provide communications for IoT networks, but numerous security and privacy issues need to be considered. In this paper, we analyze the security and the privacy of a new RFID authentication protocol proposed by Shi et al. in 2014. We prove that although Shi et al. have tried to present a secure and untraceable authentication protocol, their protocol still suffers from several security and privacy weaknesses which make it vulnerable to various security and privacy attacks. We present our privacy analysis based on a well-known formal privacy model which is presented by Ouafi and Phan in 2008. Moreover, to stop such attacks on the protocol and increase the performance of Shi et al.’s scheme, we present some modifications and propound an improved version of the protocol. Finally, the security and the privacy of the proposed protocol were analyzed against various attacks.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. Amirkabir International Journal of Electrical & Electronics Engineering (AIJ-EEE)
Keywords
Internet of thingsRFID authentication protocolsSecurity and privacyOuafi-Phan privacy modelEPC C1 G2 standard.
Contact author(s)
abdolmaleki behzad @ yahoo com
History
2016-04-19: received
Short URL
https://ia.cr/2016/387
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2016/387,
      author = {K.  Baghery and B.  Abdolmaleki and M.  J.  Emadi},
      title = {Game-Based Cryptanalysis of a Lightweight {CRC}-Based Authentication Protocol for {EPC} Tags},
      howpublished = {Cryptology {ePrint} Archive, Paper 2016/387},
      year = {2016},
      url = {https://eprint.iacr.org/2016/387}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.