Cryptanalysis of the SASI Ultralightweight RFID Authentication Protocol with Modular Rotations
| dc.creator | Hernandez-Castro, Julio C. | |
| dc.creator | Tapiador, Juan M. E. | |
| dc.creator | Peris-Lopez, Pedro | |
| dc.creator | Quisquater, Jean-Jacques | |
| dc.date | 2008-11-26 | |
| dc.date.accessioned | 2026-07-07T12:04:29Z | |
| dc.date.available | 2026-07-07T12:04:29Z | |
| dc.description | In this work we present the first passive attack over the SASI lightweight authentication protocol with modular rotations. This can be used to fully recover the secret $ID$ of the RFID tag, which is the value the protocol is designed to conceal. The attack is described initially for recovering $\lfloor log_2(96) \rfloor=6$ bits of the secret value $ID$, a result that by itself allows to mount traceability attacks on any given tag. However, the proposed scheme can be extended to obtain any amount of bits of the secret $ID$, provided a sufficiently large number of successful consecutive sessions are eavesdropped. We also present results on the attack's efficiency, and some ideas to secure this version of the SASI protocol. | |
| dc.identifier | https://arxiv.org/abs/0811.4257 | |
| dc.identifier | http://arxiv.org/abs/0811.4257 | |
| dc.identifier.uri | http://salesiana.dossiersoluciones.com/handle/123456789/208148 | |
| dc.subject | Cryptography and Security | |
| dc.title | Cryptanalysis of the SASI Ultralightweight RFID Authentication Protocol with Modular Rotations | |
| dc.type | text |