6 Ultra-lightweight Authentication
105
cyclic rotation function, which returns the string s rotated circularly to the left by
positions. The three values, A 1 , A 2 and A 3 , computed by the reader, are:
A 1 = IDS ⊕ K 1 ⊕ n 1 , A 2 = (IDS ∨ K 2 ) + n 2 , and A 3 = (K 1 ⊕ K 2 ) + (K 1 ⊕ K 2 ),
where K 1 = Rot (K 1 ⊕ n 2 , K 1 ) and K 2 = Rot (K 2 ⊕ n 1 , K 2 ). Then, the value B 1 ,
computed by the tag, is
B 1 = (K 2 + I D) ⊕ ((K 1 ⊕ K 2 ) ∨ K 1 )
The updating functions for the pseudonym and the keys are:
IDS = (IDS old + ID) ⊕ (n 2 ⊕ K 1 ), K 1 = K 1 , K 2 = K 2 ,
Having considered a sample computation, let us move to the basic requirement
for an authentication protocol, that is, correctness: if the reader and tag initiate a
protocol execution when they share at least one IDS and the corresponding sequence
of secret keys, and no adversarial action or transmission error occurs, then they
should successfully complete the execution and authenticate each other.
The main security and privacy goals in the design of ultralightweight authentication protocols are:
• Resistance to desynchronization attacks. An adversary should not be able to
desynchronize the reader and tag.
• Resistance to impersonation attacks. An adversary should not be able to
impersonate the reader to the tag or the tag to the reader.
• Anonymity and resistance to tracking attacks. The protocol should protect
against any adversarial action aiming at identifying the tag, and should guarantee
that the movements of a tag cannot be traced.
• Resistance to replay attacks. The protocol should be immune to attacks in
which an adversary collects messages from protocol executions between the
reader and tag and sends them again to the parties, in order to subvert some
of the security and privacy properties.
• Forward security. Even if at a certain point the tag is compromised and the
adversary gets the secret information stored in the tag’s memory, the past
communications should remain unaffected.
• Resistance to leakage and disclosure attacks. The protocol should not leak
secret information under adversarial actions, and there is no way to get access to
the secret information shared between the tag and reader.
Some of the above goals in certain applications should be guaranteed against
a passive adversary, who just eavesdrops on the protocol executions, while others
should hold with respect to an active adversary, who can intercept and modify the
messages and interact with the parties.
In the next section we elaborate on the security and privacy properties. Indeed,
in this area they are almost always expressed in an informal way, and as a list of
105
cyclic rotation function, which returns the string s rotated circularly to the left by
positions. The three values, A 1 , A 2 and A 3 , computed by the reader, are:
A 1 = IDS ⊕ K 1 ⊕ n 1 , A 2 = (IDS ∨ K 2 ) + n 2 , and A 3 = (K 1 ⊕ K 2 ) + (K 1 ⊕ K 2 ),
where K 1 = Rot (K 1 ⊕ n 2 , K 1 ) and K 2 = Rot (K 2 ⊕ n 1 , K 2 ). Then, the value B 1 ,
computed by the tag, is
B 1 = (K 2 + I D) ⊕ ((K 1 ⊕ K 2 ) ∨ K 1 )
The updating functions for the pseudonym and the keys are:
IDS = (IDS old + ID) ⊕ (n 2 ⊕ K 1 ), K 1 = K 1 , K 2 = K 2 ,
Having considered a sample computation, let us move to the basic requirement
for an authentication protocol, that is, correctness: if the reader and tag initiate a
protocol execution when they share at least one IDS and the corresponding sequence
of secret keys, and no adversarial action or transmission error occurs, then they
should successfully complete the execution and authenticate each other.
The main security and privacy goals in the design of ultralightweight authentication protocols are:
• Resistance to desynchronization attacks. An adversary should not be able to
desynchronize the reader and tag.
• Resistance to impersonation attacks. An adversary should not be able to
impersonate the reader to the tag or the tag to the reader.
• Anonymity and resistance to tracking attacks. The protocol should protect
against any adversarial action aiming at identifying the tag, and should guarantee
that the movements of a tag cannot be traced.
• Resistance to replay attacks. The protocol should be immune to attacks in
which an adversary collects messages from protocol executions between the
reader and tag and sends them again to the parties, in order to subvert some
of the security and privacy properties.
• Forward security. Even if at a certain point the tag is compromised and the
adversary gets the secret information stored in the tag’s memory, the past
communications should remain unaffected.
• Resistance to leakage and disclosure attacks. The protocol should not leak
secret information under adversarial actions, and there is no way to get access to
the secret information shared between the tag and reader.
Some of the above goals in certain applications should be guaranteed against
a passive adversary, who just eavesdrops on the protocol executions, while others
should hold with respect to an active adversary, who can intercept and modify the
messages and interact with the parties.
In the next section we elaborate on the security and privacy properties. Indeed,
in this area they are almost always expressed in an informal way, and as a list of
