无线射频识别(RFID)系统的匿名认证机制可以有效的保护标签的机密性,但不可避免带来可扩展的问题.对新提出的RFID无条件安全认证协议(UCS—RFID)进行了研究.指明目前已有被动攻击结果存在的错误.通过分析,UCS-RFID方案不能抵御去同步攻击,不提供无条件的安全性,并不能抵御假冒攻击,攻击者可以通过假冒合法阅读器或者标签进行交互而获得秘密信息;并给出了一个改进的方案以抵御假冒攻击.
Anonymous authentication mechanisms can be used in RFID systems to preserve the confidentiality of the RFID tags, which will cause the scalability problem inevitably. In this paper, security analysis is presented on a recently proposed protocol that has high scalability-Unconditionally Secure Anthentication Protocols (UCS-RFID protocols). The drawback of existing passive analysis out- come is presented, and the reseach shows that the UCS-RFID protocol can not provide the unconditional security as it is claimed; and can not resist the impersonation attack, for the adversary can deduce the secrets through impersonating legal reader or tag to communi- cate with legal counterpart. In addition, an improved protocol is presented to resist this attack.