Cryptanalysis of a Hash Based Mutual RFID Tag Authentication Protocol.

Da-Zhi Sun,Ji-Dong Zhong
DOI: https://doi.org/10.1007/s11277-016-3513-4
IF: 2.017
2016-01-01
Wireless Personal Communications
Abstract:Srivastava et al., recently proposed a hash based mutual RFID authentication protocol. They claimed that the protocol can provide several attractive security features, i.e., the mutual authentication and the resistance against the eavesdropping and tracing attack, the replay attack, the man-in-the-middle attack, and the desynchronization. However, we find that the protocol is vulnerable to a novel forgery attack presented in the paper. The forgery attack undermines the protocol in the mutual authentication and the resistance against both the man-in-the-middle attack and the desynchronization as claimed. In addition to the security vulnerability, the protocol is also inefficient in implementation, because it makes use of the timestamp and random number simultaneously. Therefore, the protocol is not suitable for the wireless security systems. We hope that our cryptanalysis results are useful to design more robust RFID authentication protocols for the wireless security systems in the future.
What problem does this paper attempt to address?