Breaking the Ultralightweight RFID Mutual Authentication Protocol: Confidentiality Under Threat
摘要
Radio Frequency Identification (RFID) tags collect real-time location information in IoT-based asset-tracking applications, rendering security and privacy crucial. Recently, an Ultralightweight RFID Mutual Authentication Protocol (URMAP) has been proposed, claiming to ensure confidentiality, integrity, and availability of tag/reader pair. This paper challenges the confidentiality claim of the protocol by demonstrating three secret-disclosure attack models. Probabilistic tango cryptanalysis extracts the tag’s identification information with an average success rate of 84.375%. In addition, a functional attack is executed mainly by exploiting the unbalanced nature of encryption primitives, i.e., bit-wise AND and OR operators, to receive all of the tag’s attributes deterministically. Grover’s search-based brute force attack challenges the quantum resilience of the protocol by retrieving attributes associated with all tags within the identification network. To mitigate these vulnerabilities, an enhanced protocol, URMAP