[Resource Topic] 2014/968: Attacks on Secure Ownership Transfer for Multi-Tag Multi-Owner Passive RFID Environments

Welcome to the resource topic for 2014/968

Title:
Attacks on Secure Ownership Transfer for Multi-Tag Multi-Owner Passive RFID Environments

Authors: Jorge Munilla, Mike Burmester, Albert Peinado

Abstract:

Sundaresan et al proposed recently a novel ownership transfer protocol for multi-tag multi-owner RFID environments that complies with the EPC Class1 Generation2 standard. The authors claim that this provides individual-owner privacy and prevents tracking attacks. In this paper we show that this protocol falls short of its security objectives. We describe attacks that allow: a) an eavesdropper to trace a tag, b) the previous owner to obtain the private information that the tag shares with the new owner, and c) an adversary that has access to the data stored on a tag to link this tag to previous interrogations (forward-secrecy). We then analyze the security proof and show that while the first two cases can be solved with a more careful design, for lightweight RFID applications strong privacy remains an open problem.

ePrint: https://eprint.iacr.org/2014/968

See all topics related to this paper.

Feel free to post resources that are related to this paper below.

Example resources include: implementations, explanation materials, talks, slides, links to previous discussions on other websites.

For more information, see the rules for Resource Topics .