Dynamic Key-Updating: Privacy-Preserving Authentication for RFID Systems

  • Authors:
  • Li Lu;Jinsong Han;Lei Hu;Yunhao Liu;Lionel M. Ni

  • Affiliations:
  • Graduate School of Chinese Academy of Sciences, China;Hong Kong University of Science and Technology, Hong Kong;Graduate School of Chinese Academy of Sciences, China;Hong Kong University of Science and Technology, Hong Kong;Hong Kong University of Science and Technology, Hong Kong

  • Venue:
  • PERCOM '07 Proceedings of the Fifth IEEE International Conference on Pervasive Computing and Communications
  • Year:
  • 2007

Quantified Score

Hi-index 0.01

Visualization

Abstract

The objective of private authentication for Radio Frequency Identification (RFID) systems is to allow valid readers to explicitly authenticate their dominated tags without leaking tags' private information. To achieve this goal, RFID tags issue encrypted authentication messages to the RFID reader, and the reader searches the key space to locate the tags. Due to the lack of efficient key updating algorithms, previous schemes are vulnerable to many active attacks, especially the compromising attack. In this paper, we propose a Strong and lightweight RFID Private Authentication protocol, SPA. By designing a novel key updating method, we achieve the forward secrecy in SPA with an efficient key search algorithm. We also show that, compared with existing designs, SPA is able to effectively defend against both passive and active attacks, including compromising attacks. Through prototype implementation, we observe that SPA is practical and scalable in current RFID infrastructures.