88
Internet of Things (IoT)
between one another with no requirement for alignment in the same line of sight or physical contact. An RFID is made up of two components: transponders (RFID tags) and transceivers (RFID readers).
RFID Tag (transponder) consists of a microchip, memory embedded with an antenna. The
memory unit has a unique identifier known as electronic product code (EPC). The function of the EPC in each tag is to provide a universal numerical data by which a particular
tag is recognized universally. RFID tags are classified into active and passive types. Active
tag houses a battery internally, which facilitates the interaction of its unique EPC with its
surrounding EPCs remotely from a limited distance. Passive tags function without battery
and the information relay through EPC occurs only by its activation by a transceiver from a
predefined range of the tag. Tag Readers (transceivers) are proprietary in nature and operate
in conjunction with RFID tags (active/passive). The EPC is the identifying signature of a
particular tag under the scan of the reader. The RFID reader functions as the identification
detector of each tag by its interaction with the EPC of the tag during its authentication.
In their study, Mike and Medeiros (2007) and Qinghan et al. (2009) discussed security
issues of RFID and categorized such attacks as follows: attack on authenticity, attack on
integrity, attack on confidentiality, and attack on availability.
5.5.1.1.1 Attack on Authenticity (Unauthorized Tag Disabling)
Such attacks render an RFID tag to malfunction and misbehave during the scanning of a
tag reader. Its EPC replies misinformation against the unique numerical identity assigned
to it. This type of attack is generally exhibited remotely, allowing the attacker to manipulate the tag behavior from a distance.
5.5.1.1.2 Attack on Integrity (Unauthorized Tag Cloning)
The capturing of EPC identity information and manipulation of the tags by rogue readers
falls under this category. Once the identity information of a tag is compromised, replication (cloning) of the tag is made possible which can be further used to bypass or counterfeit
security measures as well as to introduce new vulnerabilities during automatic verification processes (Qinghan et al. 2009).
5.5.1.1.3 Attack on Confidentiality (Unauthorized Tag Tracking)
A tag can be traced through rogue readers, which may result in giving up of sensitive
information (like a person’s address). From a consumer’s point of view, buying a product
having an RFID tag guarantees them no confidentiality if the tag is being tracked unauthorized. This leaks the privacy.
5.5.1.1.4 Attack on Availability (Replay Attacks)
In this case, the attacker uses a tag’s response to a rogue reader’s challenge to impersonate
the tag (Mike and Medeiros 2007). In replay attacks, the communicating signal between
the reader and the tag is intercepted, recorded, and replayed upon the receipt of any query
from the reader at a later time, thus faking the availability of the tag.
5.5.1.2 WSN Technology: Security Issues
Wireless sensor networks (WSN) consist of independent nodes where communication
(wireless) takes place over limited frequency and bandwidth. The communicating node
has sensor, memory, radio transceiver, microcontroller, and battery. Due to the limited
communication range of each sensor node, multi-hop relay of information takes place in
Internet of Things (IoT)
between one another with no requirement for alignment in the same line of sight or physical contact. An RFID is made up of two components: transponders (RFID tags) and transceivers (RFID readers).
RFID Tag (transponder) consists of a microchip, memory embedded with an antenna. The
memory unit has a unique identifier known as electronic product code (EPC). The function of the EPC in each tag is to provide a universal numerical data by which a particular
tag is recognized universally. RFID tags are classified into active and passive types. Active
tag houses a battery internally, which facilitates the interaction of its unique EPC with its
surrounding EPCs remotely from a limited distance. Passive tags function without battery
and the information relay through EPC occurs only by its activation by a transceiver from a
predefined range of the tag. Tag Readers (transceivers) are proprietary in nature and operate
in conjunction with RFID tags (active/passive). The EPC is the identifying signature of a
particular tag under the scan of the reader. The RFID reader functions as the identification
detector of each tag by its interaction with the EPC of the tag during its authentication.
In their study, Mike and Medeiros (2007) and Qinghan et al. (2009) discussed security
issues of RFID and categorized such attacks as follows: attack on authenticity, attack on
integrity, attack on confidentiality, and attack on availability.
5.5.1.1.1 Attack on Authenticity (Unauthorized Tag Disabling)
Such attacks render an RFID tag to malfunction and misbehave during the scanning of a
tag reader. Its EPC replies misinformation against the unique numerical identity assigned
to it. This type of attack is generally exhibited remotely, allowing the attacker to manipulate the tag behavior from a distance.
5.5.1.1.2 Attack on Integrity (Unauthorized Tag Cloning)
The capturing of EPC identity information and manipulation of the tags by rogue readers
falls under this category. Once the identity information of a tag is compromised, replication (cloning) of the tag is made possible which can be further used to bypass or counterfeit
security measures as well as to introduce new vulnerabilities during automatic verification processes (Qinghan et al. 2009).
5.5.1.1.3 Attack on Confidentiality (Unauthorized Tag Tracking)
A tag can be traced through rogue readers, which may result in giving up of sensitive
information (like a person’s address). From a consumer’s point of view, buying a product
having an RFID tag guarantees them no confidentiality if the tag is being tracked unauthorized. This leaks the privacy.
5.5.1.1.4 Attack on Availability (Replay Attacks)
In this case, the attacker uses a tag’s response to a rogue reader’s challenge to impersonate
the tag (Mike and Medeiros 2007). In replay attacks, the communicating signal between
the reader and the tag is intercepted, recorded, and replayed upon the receipt of any query
from the reader at a later time, thus faking the availability of the tag.
5.5.1.2 WSN Technology: Security Issues
Wireless sensor networks (WSN) consist of independent nodes where communication
(wireless) takes place over limited frequency and bandwidth. The communicating node
has sensor, memory, radio transceiver, microcontroller, and battery. Due to the limited
communication range of each sensor node, multi-hop relay of information takes place in
