Secure EPC Gen2 Compliant Radio Frequency Identification

  • Authors:
  • Mike Burmester;Breno Medeiros;Jorge Munilla;Alberto Peinado

  • Affiliations:
  • Department of Computer Science, Florida State University, Tallahassee, USA 32306;Google, Inc., USA 94043;Departamento de Ingeniería de Comunicaciones, Universidad de Málaga, Spain;Departamento de Ingeniería de Comunicaciones, Universidad de Málaga, Spain

  • Venue:
  • ADHOC-NOW '09 Proceedings of the 8th International Conference on Ad-Hoc, Mobile and Wireless Networks
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

The increased functionality of EPC Class1 Gen2 (EPCGen2) is making this standard a de facto specification for inexpensive tags in the RFID industry. Recently three EPCGen2 compliant protocols that address security issues were proposed in the literature. In this paper we analyze these protocols and show that they are not secure and subject to replay/impersonation and statistical analysis attacks. We then propose an EPCGen2 compliant RFID protocol that uses the numbers drawn from synchronized pseudorandom number generators (RNG) to provide secure tag identification and session unlinkability. This protocol is optimistic and its security reduces to the (cryptographic) pseudorandomness of the RNGs supported by EPCGen2.