100
X. Carpent et al.
operate anti-theft systems, and much more. Wireless communication plays an
important role in this landscape, especially in dealing with moving objects where
Radio and Near-Field frequencies are commonly used. In the specific case of RadioFrequency Identification (RFID), there are “Tags” and “Readers”. Tags are tiny
devices used to label objects; they contain data and communicate with the readers.
Readers are bigger devices that collect and forward information to a backend server
that processes the data. RFID tags are already widely deployed to track objects (e.g.,
goods dispatched in a distribution hub). Tags, in their most basic form, the passive
one, have no battery: they receive their energy wirelessly from the reader. Tags are
extremely cheap, with costs in the order of few cents. They are severely constrained
in terms of computing power.
In general, small devices, in all forms currently available, are the weak link in
the system (e.g., see [579] for a recent attack), and good solutions to the security
and privacy concerns are of paramount importance. In particular, authentication,
the process through which two entities confirm their identities to each other, is a
fundamental step for the development of secure applications.
6.1.2 Authentication: Protocol Classification and Physical
Constraints
Unfortunately, the authentication problem, in the ultra-lightweight setting, is a
challenging one. Indeed, the devices’ limitations severely impact the design of the
protocols. In [139] a coarse classification partitions authentication protocols into
4 categories: full-fledged, simple, lightweight, and ultra-lightweight. The division
is based on the capabilities of the constrained devices. Full-fledged protocols
allow the use of public-key and symmetric-key cryptography. Thus, they can
fully exploit standard cryptographic tools. Simple protocols rely on a limited
number of cryptographic functionalities like pseudo-random numbers generation
and hashing. Lightweight protocols further restrict the usable cryptography. They
avoid hashing, and resort to using simpler operations like CRC checksums. Finally,
ultra-lightweight protocols rely only on basic arithmetic and logical operations
(modular addition, and, or, xor, etc.).
Although the above classification does not provide an exact distinction among
the various classes, we still adopt it since it has been used in several papers
that have appeared in the literature. In this chapter we are concerned with very
small computing elements, like passive RFID tags, and with ultra-lightweight
authentication protocols for such devices. It is very likely that a large percentage
of tomorrow’s interconnected world will consist of ultra-lightweight computing
elements. Indeed, as observed in [308], although technological advances allow us to
build inexpensive devices with improved capabilities at the same price, usually the
market dictates the use of increasingly cheaper devices with the same capabilities.
Hence, we should expect to keep dealing with the least powerful ones.
X. Carpent et al.
operate anti-theft systems, and much more. Wireless communication plays an
important role in this landscape, especially in dealing with moving objects where
Radio and Near-Field frequencies are commonly used. In the specific case of RadioFrequency Identification (RFID), there are “Tags” and “Readers”. Tags are tiny
devices used to label objects; they contain data and communicate with the readers.
Readers are bigger devices that collect and forward information to a backend server
that processes the data. RFID tags are already widely deployed to track objects (e.g.,
goods dispatched in a distribution hub). Tags, in their most basic form, the passive
one, have no battery: they receive their energy wirelessly from the reader. Tags are
extremely cheap, with costs in the order of few cents. They are severely constrained
in terms of computing power.
In general, small devices, in all forms currently available, are the weak link in
the system (e.g., see [579] for a recent attack), and good solutions to the security
and privacy concerns are of paramount importance. In particular, authentication,
the process through which two entities confirm their identities to each other, is a
fundamental step for the development of secure applications.
6.1.2 Authentication: Protocol Classification and Physical
Constraints
Unfortunately, the authentication problem, in the ultra-lightweight setting, is a
challenging one. Indeed, the devices’ limitations severely impact the design of the
protocols. In [139] a coarse classification partitions authentication protocols into
4 categories: full-fledged, simple, lightweight, and ultra-lightweight. The division
is based on the capabilities of the constrained devices. Full-fledged protocols
allow the use of public-key and symmetric-key cryptography. Thus, they can
fully exploit standard cryptographic tools. Simple protocols rely on a limited
number of cryptographic functionalities like pseudo-random numbers generation
and hashing. Lightweight protocols further restrict the usable cryptography. They
avoid hashing, and resort to using simpler operations like CRC checksums. Finally,
ultra-lightweight protocols rely only on basic arithmetic and logical operations
(modular addition, and, or, xor, etc.).
Although the above classification does not provide an exact distinction among
the various classes, we still adopt it since it has been used in several papers
that have appeared in the literature. In this chapter we are concerned with very
small computing elements, like passive RFID tags, and with ultra-lightweight
authentication protocols for such devices. It is very likely that a large percentage
of tomorrow’s interconnected world will consist of ultra-lightweight computing
elements. Indeed, as observed in [308], although technological advances allow us to
build inexpensive devices with improved capabilities at the same price, usually the
market dictates the use of increasingly cheaper devices with the same capabilities.
Hence, we should expect to keep dealing with the least powerful ones.
