Cryptanalysis of the SASI Ultralightweight RFID Authentication Protocol with Modular Rotations

dc.creatorHernandez-Castro, Julio C.
dc.creatorTapiador, Juan M. E.
dc.creatorPeris-Lopez, Pedro
dc.creatorQuisquater, Jean-Jacques
dc.date2008-11-26
dc.date.accessioned2026-07-07T12:04:29Z
dc.date.available2026-07-07T12:04:29Z
dc.descriptionIn this work we present the first passive attack over the SASI lightweight authentication protocol with modular rotations. This can be used to fully recover the secret $ID$ of the RFID tag, which is the value the protocol is designed to conceal. The attack is described initially for recovering $\lfloor log_2(96) \rfloor=6$ bits of the secret value $ID$, a result that by itself allows to mount traceability attacks on any given tag. However, the proposed scheme can be extended to obtain any amount of bits of the secret $ID$, provided a sufficiently large number of successful consecutive sessions are eavesdropped. We also present results on the attack's efficiency, and some ideas to secure this version of the SASI protocol.
dc.identifierhttps://arxiv.org/abs/0811.4257
dc.identifierhttp://arxiv.org/abs/0811.4257
dc.identifier.urihttp://salesiana.dossiersoluciones.com/handle/123456789/208148
dc.subjectCryptography and Security
dc.titleCryptanalysis of the SASI Ultralightweight RFID Authentication Protocol with Modular Rotations
dc.typetext

Files

Collections