On the Designing of a Tamper Resistant Prescription RFID Access Control System

  • Authors:
  • Masoumeh Safkhani;Nasour Bagheri;Majid Naderi

  • Affiliations:
  • Electrical Engineering Department, Iran University of Science and Technology, Tehran, Iran;Electrical Engineering Department, Shahid Rajaee Teacher Training University, Tehran, Iran 16788-15811;Electrical Engineering Department, Iran University of Science and Technology, Tehran, Iran

  • Venue:
  • Journal of Medical Systems
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

Recently, Chen et al. have proposed a novel tamper resistant prescription RFID access control system, published in the Journal of Medical Systems. In this paper we consider the security of the proposed protocol and identify some existing weaknesses. The main attack is a reader impersonation attack which allows an active adversary to impersonate a legitimate doctor, e.g. the patient's doctor, to access the patient's tag and change the patient prescription. The presented attack is quite efficient. To impersonate a doctor, the adversary should eavesdrop one session between the doctor and the patient's tag and then she can impersonate the doctor with the success probability of `1'. In addition, we present efficient reader-tag to back-end database impersonation, de-synchronization and traceability attacks against the protocol. Finally, we propose an improved version of protocol which is more efficient compared to the original protocol while provides the desired security against the presented attacks.