6 Ultra-lightweight Authentication
103
reader and a backend server. The channel between the reader and the backend server
is assumed to be secure, but the channel between the reader and the tag is public and
is susceptible to attacks. To simplify the description, we say that the reader performs
some computations, even if the reader just forwards the messages and the backend
server is the real entity that performs the computations.
Each tag has a static identifier, I D, which is hard-coded into the circuit at
production time and is never revealed. Furthermore, the tag has a pseudonym, I DS,
and a few secret keys, which are stored in the tag memory, and are usually updated
after each successful execution of the protocol. All of these values are bit-strings of
up to 100 bits. Common values are 64 and 96.
Readers are expected to be able to generate random numbers or pseudo-random
numbers.
The backend server, for each tag with static identifier I D, stores in a table the
pseudonym and the keys, which therefore are shared with the tag.
The authentication protocol consists in a few rounds. Typically, four.
Figure 6.1 depicts the structure of many ultra-lightweight authentication protocols. Here we provide a description of the messages:
• The Hello message is the starting message with which the reader activates the
tag, providing it with the energy for the subsequent computation.
Authentication Protocol
g
a
T
r
e
d
a
e
R
1.
Hello
2.
IDS
3. Choose random numbers
Compute, as function of the
random numbers, the keys, and IDS,
the values A 1 , A 2 ,...,A n
A 1 ||A 2 ||...||An
Extract the random numbers
from some of the A i
s
Check the other A i
s.
If ok, accept.
Compute B 1 , B 2 ,...,B k
B 1 ||B 2 ||...||B k
4. Check B 1 , B 2 ,...,B k . If ok, accept
Fig. 6.1 General framework: steps of the authentication protocol
Précédent

- 114/268

Suivant