<p>Radio Frequency Identification (RFID) tags collect real-time location information in IoT-based asset-tracking applications, rendering security and privacy crucial. Recently, an Ultralightweight RFID Mutual Authentication Protocol (URMAP) has been proposed, claiming to ensure confidentiality, integrity, and availability of tag/reader pair. This paper challenges the confidentiality claim of the protocol by demonstrating three secret-disclosure attack models. Probabilistic tango cryptanalysis extracts the tag’s identification information with an average success rate of 84.375%. In addition, a functional attack is executed mainly by exploiting the unbalanced nature of encryption primitives, i.e., bit-wise <i>AND</i> and <i>OR</i> operators, to receive all of the tag’s attributes deterministically. Grover’s search-based brute force attack challenges the quantum resilience of the protocol by retrieving attributes associated with all tags within the identification network. To mitigate these vulnerabilities, an enhanced protocol, URMAP<InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10207_2025_1122_Article_IEq1.gif" Format="GIF" Height="10" Rendition="HTML" Resolution="72" Type="Linedraw" Width="11" /> </InlineMediaObject> <EquationSource Format="TEX">\(^+\)</EquationSource> <EquationSource Format="MATHML"><math> <mmultiscripts> <mrow /> <mrow /> <mo>+</mo> </mmultiscripts> </math></EquationSource> </InlineEquation>, is proposed, which retains the strengths of URMAP while addressing its security flaws. As a future direction, this article advocates for a paradigm shift toward post-quantum ultralightweight ciphers.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Breaking the Ultralightweight RFID Mutual Authentication Protocol: Confidentiality Under Threat

  • Parsa Riaz,
  • Madiha Khalid,
  • Mehdi Hussain,
  • Naveed Riaz,
  • Umar Mujahid,
  • Muhammad Najam-ul-islam

摘要

Radio Frequency Identification (RFID) tags collect real-time location information in IoT-based asset-tracking applications, rendering security and privacy crucial. Recently, an Ultralightweight RFID Mutual Authentication Protocol (URMAP) has been proposed, claiming to ensure confidentiality, integrity, and availability of tag/reader pair. This paper challenges the confidentiality claim of the protocol by demonstrating three secret-disclosure attack models. Probabilistic tango cryptanalysis extracts the tag’s identification information with an average success rate of 84.375%. In addition, a functional attack is executed mainly by exploiting the unbalanced nature of encryption primitives, i.e., bit-wise AND and OR operators, to receive all of the tag’s attributes deterministically. Grover’s search-based brute force attack challenges the quantum resilience of the protocol by retrieving attributes associated with all tags within the identification network. To mitigate these vulnerabilities, an enhanced protocol, URMAP \(^+\) + , is proposed, which retains the strengths of URMAP while addressing its security flaws. As a future direction, this article advocates for a paradigm shift toward post-quantum ultralightweight ciphers.