DocumentCode
1710128
Title
Exposing an effective denial of information attack from the misuse of EPCglobal standards in an RFID authentication scheme
Author
Lim, Tong-Lee ; Li, Tieyan
Author_Institution
Inst. for Infocomm Res., Singapore
fYear
2008
Firstpage
1
Lastpage
6
Abstract
In this paper, we expose a denial of information attack that is possible due to the misuse of the kill password (specified under the EPC Class-1 Gen-2 standard [1]) in a previously proposed RFID tag-reader mutual authentication scheme [2]. We show how a passive eavesdropper can obtain useful information by monitoring the authentication session involving a target tag and correlating the information received. By repeating the process over a few authentication sessions, the eavesdropper can collect enough information about the kill password to launch a successful attack to kill and disable the tag. From our simulation analysis, we find that the attack can be carried out effectively using only three to five eavesdropped sessions in most cases. In addition, we discuss the implications of this attack and describe a few other weaknesses that we have observed in the scheme.
Keywords
radiofrequency identification; telecommunication security; EPC Class-1 Gen-2 standard; EPCglobal standards; RFID tag-reader mutual authentication scheme; denial of information attack; electronic product code; Analytical models; Authentication; Code standards; Communication standards; Monitoring; RFID tags; Radiofrequency identification; Standards development; Standards organizations; Standards publication;
fLanguage
English
Publisher
ieee
Conference_Titel
Personal, Indoor and Mobile Radio Communications, 2008. PIMRC 2008. IEEE 19th International Symposium on
Conference_Location
Cannes
Print_ISBN
978-1-4244-2643-0
Electronic_ISBN
978-1-4244-2644-7
Type
conf
DOI
10.1109/PIMRC.2008.4699588
Filename
4699588
Link To Document