Security and Privacy in Two RFID Deployments , With New Methods For Private Authentication and RFID Pseudonyms

نویسنده

  • David Alexander Molnar
چکیده

We study security and privacy in deployments of Radio Frequency Identification (RFID) technology and propose novel mechanisms for improving RFID privacy. In the first part of the thesis, we consider two real deployments of RFID technology: library books and electronic passports. For each deployment, we set out security and privacy issues. Then we analyze existing RFID technology in the context of these issues. We relate these issues to concrete technical problems, such as the problem of private authentication: how can Alice and Bob determine that they share a secret key without an eavesdropper learning their identities? The second part of the thesis describes new techniques for solving these problems. We describe a symmetric-key private authentication protocol which requires work logarithmic in the number of RFID tags in a system, while all previous solutions required linear work. Then we discuss using a trusted third party called an “infomediary” to enforce a privacy policy and a way to realize the infomediary by “recoding” RFID tags. We move beyond recoding with a method for tags to generate a new one-time pseudonym on each reading. Our pseudonym scheme requires work logarithmic in the number of tags for an infomediary to learn the real tag ID from a pseudonym, while all previous schemes required linear work. A drawback is that our scheme loses some, but not all, privacy if individual tags are compromised; we show that the result is a tradeoff between privacy and reader efficiency. Our scheme also supports delegation to third parties of the ability to learn tag IDs for a limited number of reads. We show that delegation enables the transfer of an RFID-tagged item between two mutually distrustful parties. Finally, we close with open problems and future directions.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Enhancing privacy of recent authentication schemes for low-cost RFID systems

Nowadays Radio Frequency Identification (RFID) systems have appeared in lots of identification and authentication applications. In some sensitive applications, providing secure and confidential communication is very important for end-users. To this aim, different RFID authentication protocols have been proposed, which have tried to provide security and privacy of RFID users. In this paper, we a...

متن کامل

Game-Based Cryptanalysis of a Lightweight CRC-Based Authentication Protocol for EPC Tags

The term "Internet of Things (IoT)" expresses a huge network of smart and connected objects which can interact with other devices without our interposition. Radio frequency identification (RFID) is a great technology and an interesting candidate to provide communications for IoT networks, but numerous security and privacy issues need to be considered. In this paper, we analyze the security and ...

متن کامل

HMAC-Based Authentication Protocol: Attacks and Improvements

As a response to a growing interest in RFID systems such as Internet of Things technology along with satisfying the security of these networks, proposing secure authentication protocols are indispensable part of the system design. Hence, authentication protocols to increase security and privacy in RFID applications have gained much attention in the literature. In this study, security and privac...

متن کامل

Traceability improvements of a new RFID protocol based on EPC C1 G2

Radio Frequency Identification (RFID) applications have spread all over the world. In order to provide their security and privacy, researchers proposed different kinds of protocols. In this paper, we analyze the privacy of a new protocol, proposed by Yu-Jehn in 2015 which is based on Electronic Product Code Class1 Generation 2 (EPC C1 G2) standard. By applying the Ouafi_Phan privacy model, we s...

متن کامل

Privacy and Security in Library RFID Issues, Practices, and Architectures

We expose privacy issues related to Radio Frequency Identification (RFID) in libraries, describe current deployments, and suggest novel architectures for library RFID. Libraries are a fast growing application of RFID; the technology promises to relieve repetitive strain injury, speed patron self-checkout, and make possible comprehensive inventory. Unlike supply-chain RFID, library RFID requires...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2006