Zhao Zhenguo
School of Water Conservancy, North China University of Water Resources and Electric Power, Zhengzhou, China,
J Med Syst. 2014 May;38(5):46. doi: 10.1007/s10916-014-0046-9. Epub 2014 Apr 23.
With the fast advancement of the wireless communication technology and the widespread use of medical systems, the radio frequency identification (RFID) technology has been widely used in healthcare environments. As the first important protocol for ensuring secure communication in healthcare environment, the RFID authentication protocols derive more and more attentions. Most of RFID authentication protocols are based on hash function or symmetric cryptography. To get more security properties, elliptic curve cryptosystem (ECC) has been used in the design of RFID authentication protocol. Recently, Liao and Hsiao proposed a new RFID authentication protocol using ECC and claimed their protocol could withstand various attacks. In this paper, we will show that their protocol suffers from the key compromise problem, i.e. an adversary could get the private key stored in the tag. To enhance the security, we propose a new RFID authentication protocol using ECC. Detailed analysis shows the proposed protocol not only could overcome weaknesses in Liao and Hsiao's protocol but also has the same performance. Therefore, it is more suitable for healthcare environments.
随着无线通信技术的快速发展以及医疗系统的广泛应用,射频识别(RFID)技术已在医疗环境中得到广泛使用。作为确保医疗环境中安全通信的首个重要协议,RFID认证协议越来越受到关注。大多数RFID认证协议基于哈希函数或对称密码学。为了获得更多安全特性,椭圆曲线密码系统(ECC)已被用于RFID认证协议的设计中。最近,廖和萧提出了一种使用ECC的新型RFID认证协议,并声称他们的协议能够抵御各种攻击。在本文中,我们将表明他们的协议存在密钥泄露问题,即攻击者可以获取存储在标签中的私钥。为了增强安全性,我们提出了一种使用ECC的新型RFID认证协议。详细分析表明,所提出的协议不仅可以克服廖和萧协议中的弱点,而且具有相同的性能。因此,它更适合医疗环境。