• DocumentCode
    2216975
  • Title

    Studying the pseudo random number generator of a low-cost RFID tag

  • Author

    Merhi, Mohamad ; Hernandez-Castro, Julio Cesar ; Peris-Lopez, Pedro

  • Author_Institution
    Fac. of Technol., Univ. of Portsmouth, Portsmouth, UK
  • fYear
    2011
  • fDate
    15-16 Sept. 2011
  • Firstpage
    381
  • Lastpage
    385
  • Abstract
    Due to severe limitations in their computational and storage capabilities, many low-cost RFID tags have been shown to implement quite weak authentication protocols, largely due to weakness in their pseudorandom number generators (PRNG). This aim of this is to examine the PRNG in use within the authentication protocol of the new NXP MIFARE Ultralight C RFID low-cost card. The article investigates the nonces generated by the card during the authentication protocol to assess their randomness, and to test any possible attacks down this path. We confirm the validity of the methodology by applying similar techniques to the Mifare 1K Classic, confirming previously discovered weaknesses. We conclude that in the light of our analysis, the PRNG of the Ultralight C is a major improvement over that of the Mifare 1K, and that the nonces generated by the former can´t be easily distinguished from truly random ones.
  • Keywords
    protocols; radiofrequency identification; random number generation; NXP MIFARE ultralight C RFID low-cost card; PRNG; authentication protocols; computational capability; low-cost RFID tag; pseudo random number generator; storage capability; Authentication; Encryption; NIST; Privacy; Protocols; Radiofrequency identification;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    RFID-Technologies and Applications (RFID-TA), 2011 IEEE International Conference on
  • Conference_Location
    Sitges
  • Print_ISBN
    978-1-4577-0028-6
  • Type

    conf

  • DOI
    10.1109/RFID-TA.2011.6068666
  • Filename
    6068666