Full Secret Disclosure Attack against an EPC- C۱ G۲ Compliant Authentication Protocol
عنوان مقاله: Full Secret Disclosure Attack against an EPC- C۱ G۲ Compliant Authentication Protocol
شناسه ملی مقاله: JR_JCSE-6-1_003
منتشر شده در در سال 1398
شناسه ملی مقاله: JR_JCSE-6-1_003
منتشر شده در در سال 1398
مشخصات نویسندگان مقاله:
Masoumeh Safkhani - Shahid Rajaee Teacher Training University
خلاصه مقاله:
Masoumeh Safkhani - Shahid Rajaee Teacher Training University
Security analysis of a protocol is an important step toward the public trust on its security. Recently, in ۲۰۱۸, Moradi et al. considered the security of the Wei and Zhang RFID EPC-C۱ G۲ compliant authentication protocol and presented desynchronization attack and also server/reader impersonation attack against it. Then they proposed an improved version of the protocol. However, in this paper as the first third-party analysis of this protocol to the best of our knowledge, we present an efficient secret disclosure attack with the complexity of only two runs of protocol and doing O(۲^{۱۶}) PRNG offline evaluations. We also recommend that designing a secure protocol by using ۱۶-bit CRCs and ۱۶-bit PRNGs in the framework of EPC-C۱ G۲ may not be possible and changing this standard to allow the use of lightweight cryptographic functions should be inevitable. In this line, we present an improved version of the Moradi et al.protocol and also prove its security both informally and formally, through GNY logic.
کلمات کلیدی: RFID, EPC-C۱ G۲, Authentication Protocol, Secret Disclosure Attack, GNY Logic
صفحه اختصاصی مقاله و دریافت فایل کامل: https://civilica.com/doc/1151390/