摘要
分析了射频识别(RFID)系统中匿名RFID认证协议(ARAP)存在的安全缺陷,指出攻击者可利用该协议存在的异或运算使用不当的安全缺陷发起身份假冒攻击.为此,提出了一种改进的RFID双向认证协议,该协议修改了ARAP认证协议中部分异或运算和验证操作,仍采用假名机制提供隐私性保护,防止攻击者对标签进行跟踪.结果分析表明,改进后的协议具有双向认证、前向安全性和匿名性等安全属性,并能够抵抗冒充、跟踪和重放等攻击.同时,性能对比分析表明改进后的协议具有比较好的效率,实用性较强.
A radio frequency identification (RFID) authentication protocol anonymous RFID authentication protocol (ARAP) protocol is analyzed. It is proved that ARAP protocol is vulnerable to impersonating attacks. An im proved RFID mutual authentication protocol is proposed in this paper. Security analysis shows that the improved protocol can achieve mutual and anonymous authentication. The improved protocol is also resistant to impersonating attacks, tracking attacks and replay attacks. Moreover, comparing with other protocols, the improved protocol is more efficient.
出处
《武汉大学学报(理学版)》
CAS
CSCD
北大核心
2012年第6期526-530,共5页
Journal of Wuhan University:Natural Science Edition
基金
河南省基础与前沿技术研究计划项目(122300410123)
郑州市科技攻关项目(10PTGG340-4)资助
关键词
射频识别
安全协议
身份认证
HASH函数
radio frequency identification (RFID)
cryptographic protocol
authentication
Hash function