• DocumentCode
    1710128
  • Title

    Exposing an effective denial of information attack from the misuse of EPCglobal standards in an RFID authentication scheme

  • Author

    Lim, Tong-Lee ; Li, Tieyan

  • Author_Institution
    Inst. for Infocomm Res., Singapore
  • fYear
    2008
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    In this paper, we expose a denial of information attack that is possible due to the misuse of the kill password (specified under the EPC Class-1 Gen-2 standard [1]) in a previously proposed RFID tag-reader mutual authentication scheme [2]. We show how a passive eavesdropper can obtain useful information by monitoring the authentication session involving a target tag and correlating the information received. By repeating the process over a few authentication sessions, the eavesdropper can collect enough information about the kill password to launch a successful attack to kill and disable the tag. From our simulation analysis, we find that the attack can be carried out effectively using only three to five eavesdropped sessions in most cases. In addition, we discuss the implications of this attack and describe a few other weaknesses that we have observed in the scheme.
  • Keywords
    radiofrequency identification; telecommunication security; EPC Class-1 Gen-2 standard; EPCglobal standards; RFID tag-reader mutual authentication scheme; denial of information attack; electronic product code; Analytical models; Authentication; Code standards; Communication standards; Monitoring; RFID tags; Radiofrequency identification; Standards development; Standards organizations; Standards publication;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Personal, Indoor and Mobile Radio Communications, 2008. PIMRC 2008. IEEE 19th International Symposium on
  • Conference_Location
    Cannes
  • Print_ISBN
    978-1-4244-2643-0
  • Electronic_ISBN
    978-1-4244-2644-7
  • Type

    conf

  • DOI
    10.1109/PIMRC.2008.4699588
  • Filename
    4699588