Strong authentication and strong integrity (SASI) is not that strong

Avoine, Gildas;Carpent, Xavier;Martin, Benjamin
(2010) 6th international conference on Radio frequency identification: security and privacy issues — Location: Istanbul, Turkey (8.June.2010)

Files

AvoineCM-2010-rfidsec.pdf
  • Restricted Access
  • Adobe PDF
  • 192.5 KB

Details

Authors
  • Avoine, GildasUCLouvain
    Author
  • Carpent, XavierUCLouvain
    Author
  • Martin, BenjaminUCLouvain
    Author
Abstract
In this work, we present a practical passive attack on SASI,an ultra-lightweight mutual authentication protocol for RFID. This attack can be used to reveal with overwhelming probability the secret ID of the prover by eavesdropping about 217 authentications. The result dismantles SASI and, more generally, provides a new approach that threatens ultraightweight authentication protocols.
Affiliations

Citations

Avoine, G., Carpent, X., & Martin, B. (2010). Strong authentication and strong integrity (SASI) is not that strong. Proceedings of the 6th international conference on Radio frequency identification: security and privacy issues, p. 50-64. https://hdl.handle.net/2078.5/221693