Please use this identifier to cite or link to this item: http://hdl.handle.net/10609/109802
Title: A practical implementation attack on weak pseudorandom number generator designs for EPC Gen2 tags
Author: Melià-Seguí, Joan  
Garcia-Alfaro, Joaquin  
Herrera-Joancomartí, Jordi  
Others: Universitat Oberta de Catalunya. Internet Interdisciplinary Institute (IN3)
Institut Mines-Télécom
Universitat Autònoma de Barcelona (UAB)
Citation: Melià Seguí, J., García Alfaro, J. & Herrera-Joancomartí, J. (2011). A Practical Implementation Attack on Weak Pseudorandom Number Generator Designs for EPC Gen2 Tags. Wireless Personal Communications, 59(1), 27-42. doi: 10.1007/s11277-010-0187-1
Abstract: The Electronic Product Code Generation 2 (EPC Gen2) is an international standard that proposes the use of Radio Frequency Identification (RFID) in the supply chain. It is designed to balance cost and functionality. As a consequence, security on board of EPC Gen2 tags is often minimal. It is, indeed, mainly based on the use of on board pseudorandomness, used to obscure the communication between readers and tags; and to acknowledge the proper execution of password-protected operations. In this paper, we present a practical implementation attack on a weak pseudorandom number generator (PRNG) designed specifically for EPC Gen2 tags. We show that it is feasible to eavesdrop a small amount of pseudorandom values by using standard EPC commands and using them to determine the PRNG configuration that allows to predict the complete output sequence.
Keywords: RFID
EPC Gen2
PRNG
security
eavesdropping
attack
implementation
DOI: 10.1007/s11277-010-0187-1
Document type: info:eu-repo/semantics/article
Version: info:eu-repo/semantics/acceptedVersion
Issue Date: 26-Nov-2010
Publication license: http://creativecommons.org/licenses/by-nc-nd/3.0/es/  
Appears in Collections:Articles cientÍfics
Articles

Files in This Item:
File Description SizeFormat 
Melia_Garcia_Herrera_WPC_2010_post.pdfPost-print280,73 kBAdobe PDFThumbnail
View/Open