Suppr超能文献

物联网设备安全:挑战“基于物理不可克隆函数的轻量级 RFID 相互认证协议”。

IoT Device Security: Challenging "A Lightweight RFID Mutual Authentication Protocol Based on Physical Unclonable Function".

机构信息

Department of Management and Technology, Université du Québec à Montréal (UQAM), Montreal, QC H2X 1L7, Canada.

Electrical Engineering Department, Shahid Rajaee Teacher Training University, Tehran 16788-15811, Iran.

出版信息

Sensors (Basel). 2018 Dec 15;18(12):4444. doi: 10.3390/s18124444.

Abstract

With the exponential increase of Internet of things (IoT) connected devices, important security risks are raised as any device could be used as an attack channel. This preoccupation is particularly important with devices featuring limited processing power and memory capabilities for security purposes. In line with this idea, Xu et al. (2018) proposed a lightweight Radio Frequency Identification (RFID) mutual authentication protocol based on Physical Unclonable Function (PUF)-ensuring mutual tag-reader verification and preventing clone attacks. While Xu et al. claim that their security protocol is efficient to protect RFID systems, we found it still vulnerable to a desynchronization attack and to a secret disclosure attack. Hence, guidelines for the improvements to the protocol are also suggested, for instance by changing the structure of the messages to avoid trivial attacks. In addition, we provide an explicit protocol for which our formal and informal security analysis have found no weaknesses.

摘要

随着物联网(IoT)连接设备的指数级增长,任何设备都可能被用作攻击渠道,这引发了重要的安全风险。对于那些出于安全目的而具有有限处理能力和内存能力的设备,这种关注尤为重要。基于这一理念,Xu 等人(2018 年)提出了一种基于物理不可克隆函数(PUF)的轻量级射频识别(RFID)相互认证协议——确保标签-读写器相互验证,并防止克隆攻击。虽然 Xu 等人声称他们的安全协议能够有效地保护 RFID 系统,但我们发现它仍然容易受到去同步攻击和秘密泄露攻击。因此,还建议对协议进行改进,例如通过改变消息的结构来避免简单的攻击。此外,我们还提供了一个明确的协议,我们对其进行了正式和非正式的安全分析,没有发现任何弱点。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/5806/6308613/3c0952fede3d/sensors-18-04444-g001.jpg

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验