Logo image
The Study on Authentication Scheme for RFID
Dissertation

The Study on Authentication Scheme for RFID

Wei, Chia-Hui
Doctor of Philosophy (PHD), 國立清華大學, 資訊工程學系
2010

Abstract

無線射頻 驗證 安全性 隱私權 RFID Authentication Secruity Privacy
Radio Frequency Identification (RFID) is the most widely adopted identification system worldwide. However, these tags are installed in an open environment to identify trade items, logistic units, assets and their locations. When a customer buys an item and takes it home, if the tag is still active, an attacker may be able to track the customer or learn what the customer is carrying in his/her bags by scanning the RFID tags. This scanning ultimately results in a privacy violation. Another problem is security; an attacker with a tag's ID can cheat the server and be wrongfully authenticated. Most methods of improving security and privacy in RFID systems fall into one of two groups: physical methods and cryptographic methods. Physical methods cannot be used with various applications within the RFID system. Furthermore, traditional encryption methods are not suitable for use in RFID systems because the tags are limited in terms of processing units and memory. The hash chain is a cryptography approach used in micro-payment systems and RFID systems. Lamport describes the construction of hash chains by using a one-way hash function to generate an initial value. In this thesis, the focus is on RFID system. An RFID system based on three components: the tags, readers, and backend servers is called an original RFID system. This thesis introduces a low-cost RFID authentication scheme used in these original RFID systems as a means of improve on previous methods but points out that this system is still vulnerable to de-synchronization attacks. Second, it addresses the RFID systems based on portable readers, which are referred to as a serverless RFID. This thesis presents the security authentication scheme developed as a means of improving on the previous method, which is nevertheless vulnerable to de-synchronization and tracking and does not allow for mutual authentication. The third RFID system presented involves the use of mobile agent devices and is called a mobile RFID. The processing units and memory of the tag are limited, so the tag can only perform simple arithmetic operations. To counter this weakness, previous researchers proposed the mobile agent for RFID privacy protection (MARP) system as a means of strengthening tag function. Other research is presented that improves on the MARP system because, again, that system is vulnerable to the tracking. However, even the improved system is still vulnerable to tracking and the use of cloning tags. This thesis ultimately proposes the use of an improved scheme to resolve this problem. Fourthly, this thesis proposes the use of a new security scheme based on ownership transfer and traceability in which secure tag ownership is transferred after ownership changes but the server is still able to trace the item. The performance of all of the aforementioned methods has been evaluated via security analysis. The analysis results indicate that the new methods proposed are indeed superior to other state-of-the-art schemes. Furthermore, we improve the performance of the ownership transfer and traceability scheme in distributions database to resist de-synchronization attack. Additionally, we extend the authentication scheme for traceability in supply chain management.

Metrics

1 Record Views

Details

Logo image