Exposing an effective denial of information attack from the misuse of EPCglobal standards in an RFID authentication scheme

T. Lim, Tieyan Li
{"title":"Exposing an effective denial of information attack from the misuse of EPCglobal standards in an RFID authentication scheme","authors":"T. Lim, Tieyan Li","doi":"10.1109/PIMRC.2008.4699588","DOIUrl":null,"url":null,"abstract":"In this paper, we expose a denial of information attack that is possible due to the misuse of the kill password (specified under the EPC Class-1 Gen-2 standard [1]) in a previously proposed RFID tag-reader mutual authentication scheme [2]. We show how a passive eavesdropper can obtain useful information by monitoring the authentication session involving a target tag and correlating the information received. By repeating the process over a few authentication sessions, the eavesdropper can collect enough information about the kill password to launch a successful attack to kill and disable the tag. From our simulation analysis, we find that the attack can be carried out effectively using only three to five eavesdropped sessions in most cases. In addition, we discuss the implications of this attack and describe a few other weaknesses that we have observed in the scheme.","PeriodicalId":125554,"journal":{"name":"2008 IEEE 19th International Symposium on Personal, Indoor and Mobile Radio Communications","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2008-12-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2008 IEEE 19th International Symposium on Personal, Indoor and Mobile Radio Communications","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/PIMRC.2008.4699588","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6

Abstract

In this paper, we expose a denial of information attack that is possible due to the misuse of the kill password (specified under the EPC Class-1 Gen-2 standard [1]) in a previously proposed RFID tag-reader mutual authentication scheme [2]. We show how a passive eavesdropper can obtain useful information by monitoring the authentication session involving a target tag and correlating the information received. By repeating the process over a few authentication sessions, the eavesdropper can collect enough information about the kill password to launch a successful attack to kill and disable the tag. From our simulation analysis, we find that the attack can be carried out effectively using only three to five eavesdropped sessions in most cases. In addition, we discuss the implications of this attack and describe a few other weaknesses that we have observed in the scheme.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
暴露了RFID认证方案中EPCglobal标准误用导致的有效信息拒绝攻击
在本文中,我们揭示了在先前提出的RFID标签-读取器相互认证方案[2]中,由于误用终止密码(根据EPC Class-1 Gen-2标准[1]指定)而可能发生的拒绝信息攻击。我们展示了被动窃听者如何通过监视涉及目标标签的身份验证会话并关联接收到的信息来获取有用的信息。通过在几个身份验证会话中重复这个过程,窃听者可以收集到关于终止密码的足够信息,从而发起成功的攻击来终止和禁用标签。通过仿真分析,我们发现在大多数情况下,只需使用三到五个窃听会话就可以有效地进行攻击。此外,我们还讨论了这种攻击的含义,并描述了我们在该方案中观察到的其他一些弱点。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Throughput optimization for multipath unicast routing under probabilistic jamming Direct transmission protection in IEEE 802.11 networks Transmit power formulation for relay-enhanced UMTS using simulation and theory Informed spectrum usage in cognitive radio networks: Interference cartography Comparative study of four modified timing metrics for the frame synchronization in OFDMA mode of WMAN
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1