110
X. Carpent et al.
employed CRC (as recommended by the EPC-C1-G2 standard), but instead of
using them as a simple error detection tool, employed them for encryption. In their
idealized model, they identified their CRC usage as equivalent to encryption, so
some of the BAN logic rules (for example R1: the message-meaning rule) did
not hold anymore. This constitutes a common mistake, as an idealized scenario
like the one modeled by BAN logic (with perfect, unbreakable and zero-leaking
ciphers) never accurately models reality. The level of abstraction needed in the
modeling phase basically makes it impractical for most realistic situations. This
is, unfortunately, not only a limitation of BAN logic but, to different extents, is also
in most formal models (GNY, etc.).
6.4 Towards a Sound Approach
6.4.1 State of the Literature
RFID technology has prompted many interesting challenges in the security and
privacy research community, and designing a secure authentication protocol for very
low-end tags is definitely one of them.
The field, however, has been the victim of an abundance of papers of dubious
quality. Many research results either repeat mistakes (for new schemes) or past
achievements (for attacks) or both. Recent protocols, with respect to previous ones,
have been enhanced by using more involved transforms of the data stored in the
tag’s memory. However, the mistakes appear to be repeated: poor design choices, a
lack of confusion and diffusion in the transforms, and informal fallacious security
analyses to support the security claims [170]. This bad reputation, combined with a
decline of interest in RFID security research as a whole, may have scared off many
seasoned cryptographers, and contributed to the relative stagnation of the field.
Despite the current situation, which may seem to indicate that ultra-lightweight
protocols are bound to fail, there is no clear evidence that designing a secure
protocol with such constraints is impossible.
The field may nowadays be inactive, but there are many unanswered questions
(and indeed, no practical, concrete, and trusted protocol emerged from it). While
it is likely to reappear under a different guise, the problem of designing a secure
authentication protocol while minimizing some aspects of its design (e.g., gate
count), is not going away, and remains an interesting research question.
6.4.2 Promising Avenues
The need for cryptographic building blocks in low-end systems is definitely
not unique to ultra-lightweight authentication protocols. A much larger research
X. Carpent et al.
employed CRC (as recommended by the EPC-C1-G2 standard), but instead of
using them as a simple error detection tool, employed them for encryption. In their
idealized model, they identified their CRC usage as equivalent to encryption, so
some of the BAN logic rules (for example R1: the message-meaning rule) did
not hold anymore. This constitutes a common mistake, as an idealized scenario
like the one modeled by BAN logic (with perfect, unbreakable and zero-leaking
ciphers) never accurately models reality. The level of abstraction needed in the
modeling phase basically makes it impractical for most realistic situations. This
is, unfortunately, not only a limitation of BAN logic but, to different extents, is also
in most formal models (GNY, etc.).
6.4 Towards a Sound Approach
6.4.1 State of the Literature
RFID technology has prompted many interesting challenges in the security and
privacy research community, and designing a secure authentication protocol for very
low-end tags is definitely one of them.
The field, however, has been the victim of an abundance of papers of dubious
quality. Many research results either repeat mistakes (for new schemes) or past
achievements (for attacks) or both. Recent protocols, with respect to previous ones,
have been enhanced by using more involved transforms of the data stored in the
tag’s memory. However, the mistakes appear to be repeated: poor design choices, a
lack of confusion and diffusion in the transforms, and informal fallacious security
analyses to support the security claims [170]. This bad reputation, combined with a
decline of interest in RFID security research as a whole, may have scared off many
seasoned cryptographers, and contributed to the relative stagnation of the field.
Despite the current situation, which may seem to indicate that ultra-lightweight
protocols are bound to fail, there is no clear evidence that designing a secure
protocol with such constraints is impossible.
The field may nowadays be inactive, but there are many unanswered questions
(and indeed, no practical, concrete, and trusted protocol emerged from it). While
it is likely to reappear under a different guise, the problem of designing a secure
authentication protocol while minimizing some aspects of its design (e.g., gate
count), is not going away, and remains an interesting research question.
6.4.2 Promising Avenues
The need for cryptographic building blocks in low-end systems is definitely
not unique to ultra-lightweight authentication protocols. A much larger research
