Security Enhancement for a Novel Mutual Authentication Scheme Based on Quadratic Residues for RFID Systems
Han-Cheng Hsiang, Hsiang-Chou Kuo, Wei‐Kuan Shih
Abstract
Han-Cheng Hsiang, Hsiang-Chou Kuo, Wei‐Kuan Shih
Abstract
In 2004, Ari Juels [1] proposed a Yoking-Proofs protocol for RFID systems. The goal is to permit tags to generate a proof which is verifiable off-line by a trusted entity even when the readers are potentially untrusted. But the protocol not only doesn¿t possess the anonymity property but also suffers from both the replay and off-line attacks. In 2005, Wong et al. [3] proposed an authentication scheme on RFID passive tags, attempting to as a standard for apparel products. However, the protocol suffers from the known-plain text attack. Recently Chou et al. proposed a scheme to improve both of the above schemes and claimed that their scheme is anonymous. In this paper, we point out that Chou et al.¿s scheme is vulnerable to the replay attack, the reflection attack and the server spoofing attack. A modification of Chou et al.¿s scheme to enhance their security is proposed. Our scheme is suitable for applications with high security requirement.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
In 2004, Ari Juels [1] proposed a Yoking-Proofs protocol for RFID systems. The goal is to permit tags to generate a proof which is verifiable off-line by a trusted entity even when the readers are potentially untrusted. But the protocol not only doesn¿t possess the anonymity property but also suffers from both the replay and off-line attacks. In 2005, Wong et al. [3] proposed an authentication scheme on RFID passive tags, attempting to as a standard for apparel products. However, the protocol suffers from the known-plain text attack. Recently Chou et al. proposed a scheme to improve both of the above schemes and claimed that their scheme is anonymous. In this paper, we point out that Chou et al.¿s scheme is vulnerable to the replay attack, the reflection attack and the server spoofing attack. A modification of Chou et al.¿s scheme to enhance their security is proposed. Our scheme is suitable for applications with high security requirement.
Key concepts: Replay attack, Reflection attack, Computer science, Mutual authentication, Scheme (mathematics), Computer security, Anonymity, Authentication (law)