该文分析一种能抵抗位置跟踪的基于哈希函数的射频识别认证协议,指出其并不能有效抵抗位置跟踪,阅读器假冒、重放攻击等,并提出一种改进的能抵抗位置跟踪的射频识别认证协议。改进协议中标签和阅读器都产生随机数,标签通过阅读器认证后服务器才对标签进行认证,同时在服务器对标签认证前标签更新其密钥。分析表明,该协议在保持原计算量和存储量的基础上能有效抵抗位置跟踪、重放攻击和假冒阅读器攻击。
A location-privacy-protected RFID authentication protocol is analyzed,it's pointed out that it can't effectively resist location racking,reader impersonation,replay attack,and an improved location-privacy-protected protocol is proposed.In the new protocol,random numbers are generated by both of the tags and readers,the server authenticates it after the reader authenticates the tag,at the same time,the tag updates its secret key before the server authenticates it.Analysis shows that the protocol can effectively resist replay attack and position tracking on the basis of keeping original computation cost and storage cost.