Security Analysis of the SASI Protocol

Tianjie Cao,Elisa Bertino,Hong Lei
DOI: https://doi.org/10.1109/tdsc.2008.32
2008-01-01
IEEE Transactions on Dependable and Secure Computing
Abstract:The ultralightweight RFID protocols only involve simple bit-wise operations (like XOR, AND, OR, etc.) on tags. In this paper, we show that the ultralightweight strong authentication and strong integrity (SASI) protocol has two security vulnerabilities, namely denial-of-service (DoS) and anonymity tracing based on a compromised tag. The former permanently disables the authentication capability of a RFID tag by destroying synchronization between the tag and the RFID reader. The latter links a compromised tag with past actions performed on this tag.
What problem does this paper attempt to address?