• DocumentCode
    3408926
  • Title

    A mutual authentication protocol for low-cost RFID tags formally verified using CasperFDR and AVISPA

  • Author

    Abughazalah, Sarah ; Markantonakis, Kostantinos ; Mayes, Keith

  • Author_Institution
    Smart Card Centre-Inf. Security Group (SCC-ISG), Univ. of London, Egham, UK
  • fYear
    2013
  • fDate
    9-12 Dec. 2013
  • Firstpage
    44
  • Lastpage
    51
  • Abstract
    Although Radio Frequency IDentification (RFID) systems offer many remarkable characteristics, security and privacy concerns are not easy to address. In this paper, we aim to overcome some of the significant privacy and security concerns by proposing a simple and lightweight RFID mutual authentication protocol. Our protocol is utilising hash functions and simple bitwise operations in an attempt to extract the strengths found in previous protocols and avoid their deficiencies. We found that the majority of the proposed protocols fail to resist DoS attacks when the attacker blocks the messages exchanged between the reader and tag more than once. Moreover, recent research focused on the security side and ignored performance. Our proposed protocol aims to solve these issues. We provide an informal analysis along with automated formal analysis using CasperFDR and AVISPA. The results show that the proposed protocol guarantees secret data secrecy and authentication under the presence of a passive adversary.
  • Keywords
    Internet; cryptographic protocols; data privacy; radiofrequency identification; telecommunication security; AVISPA; CasperFDR; DoS attack; automated formal analysis; automated validation of Internet security protocols and application; data secrecy; failure-divergence refinement; informal analysis; lightweight RFID mutual authentication protocol; message exchange; privacy concern; radio frequency identification; security; Authentication; Computer crime; Privacy; Protocols; Radiofrequency identification; Servers; AVISPA; CasperFDR; RFID; mutual authentication; privacy; security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Internet Technology and Secured Transactions (ICITST), 2013 8th International Conference for
  • Conference_Location
    London
  • Type

    conf

  • DOI
    10.1109/ICITST.2013.6750160
  • Filename
    6750160