摘要
为了确保RFID系统中用户安全风险、隐私及数据安全,分析了相关RFID协议的安全性问题,利用椭圆曲线离散对数问题的难解性,结合一次性口令OTP,提出了一种基于ECC口令认证的RFID双向认证协议。该协议实现了密钥同步更新,读写器与标签、标签与服务器之间的双向认证,有效地抵抗了重放、伪装、流量分析及跟踪等攻击。协议能很好地保护用户的隐私和数据的安全,具有密钥长度短、计算量小及安全性高等特点。
In order to decrease user’s security risks,and ensure user’s privacy and data security in the RFID systems,Analysis of the security problems of RFID protocol,combined with the intractability of the elliptic curve discrete logarithm problem and one-time password OTP,RFID,a mutual authentication protocol is proposed based on ECC password authentication. The protocol realizes the key synchronization update,and the mutual authentication between the reader and tags,labels and the server,effectively resists the attacks from replay,masquerading,traffic analysis and tracking. The protocol can protect user privacy and data security,it has such advantages as short key length,small amount of calculation,and higher security.
出处
《电脑开发与应用》
2014年第5期37-39,共3页
Computer Development & Applications
基金
国家自然科学基金(21373132)
陕西省教育厅科研计划项目(12JK0946)
关键词
RFID
椭圆曲线离散对数问题
口令认证
ECC
RFID
ECC
Radio Frequency Identification
elliptic curve discrete logarithm problem
password authentication
elliptic curve cryptosystem