Pharmacogenomics · 2008 · 30 citations · 8 references
Massive RFID deployments face privacy and data integrity challenges, and current privacy‑preserving authentication schemes, which rely on secret‑key cryptography and data updates for untraceability, remain vulnerable to denial‑of‑service attacks, yet no formal framework exists to compare their resilience. This work introduces a new characterization, synchronizability, to assess and improve RFID authentication schemes. Using synchronizability, the authors define a relevant model, evaluate existing schemes to expose deficiencies, and propose a new scheme that satisfies all desired security features.
Massively deploying RFID systems, while preserving people’s privacy and data integrity, is a major security challenge of the coming years. This is why research related to privacy-preserving authentication is growing, including design of schemes, cryptanalysis and security models. In nearly all such schemes secret key cryptography is used, since RFID tags are extremely constrained in time and space, and untraceability is achieved by updating some data at each authentication. Unfortunately, none of them entirely resists to denial of service attacks, those in which the enemy forces updating of the tag and/or the reader by sending fake messages. Moreover, literature lacks a clear and formal way of comparing schemes w.r.t. this kind of attack. In this paper, we introduce a new characterization, called synchronizability. This allows us to, first, establish a relevant model; second, evaluate existing schemes in this model and point out their deficiencies; third, present a new scheme with all desired features.
8
Defining Strong Privacy for RFID
Ari Juels, Stephen A. Weis · 2007 · 260 citations
Radu-Ioan Paise, Serge Vaudenay · 2008 · 142 citations · Full text