Skip to main page content
U.S. flag

An official website of the United States government

Dot gov

The .gov means it’s official.
Federal government websites often end in .gov or .mil. Before sharing sensitive information, make sure you’re on a federal government site.

Https

The site is secure.
The https:// ensures that you are connecting to the official website and that any information you provide is encrypted and transmitted securely.

Access keys NCBI Homepage MyNCBI Homepage Main Content Main Navigation
Review
. 2021 Aug 30;21(17):5824.
doi: 10.3390/s21175824.

Survey: Vulnerability Analysis of Low-Cost ECC-Based RFID Protocols against Wireless and Side-Channel Attacks

Affiliations
Review

Survey: Vulnerability Analysis of Low-Cost ECC-Based RFID Protocols against Wireless and Side-Channel Attacks

Souhir Gabsi et al. Sensors (Basel). .

Abstract

The radio frequency identification (RFID) system is one of the most important technologies of the Internet of Things (IoT) that tracks single or multiple objects. This technology is extensively used and attracts the attention of many researchers in various fields, including healthcare, supply chains, logistics, asset tracking, and so on. To reach the required security and confidentiality requirements for data transfer, elliptic curve cryptography (ECC) is a powerful solution, which ensures a tag/reader mutual authentication and guarantees data integrity. In this paper, we first review the most relevant ECC-based RFID authentication protocols, focusing on their security analysis and operational performances. We compare the various lightweight ECC primitive implementations designed for RFID applications in terms of occupied area and power consumption. Then, we highlight the security threats that can be encountered considering both network attacks and side-channel attacks and analyze the security effectiveness of RFID authentication protocols against such types of attacks. For this purpose, we classify the different threats that can target an ECC-based RFID system. After that, we present the most promising ECC-based protocols released during 2014-2021 by underlining their advantages and disadvantages. Finally, we perform a comparative study between the different protocols mentioned regarding network and side-channel attacks, as well as their implementation costs to find the optimal one to use in future works.

Keywords: ECC; RFID; SCA; attacks; cryptography; lightweight.

PubMed Disclaimer

Conflict of interest statement

The authors declare no conflict of interest.

Figures

Figure 1
Figure 1
RFID system operation [34].
Figure 2
Figure 2
RFID application domains [38].
Figure 3
Figure 3
Liao’s authentication protocol.
Figure 4
Figure 4
Alamr’s authentication protocol.

Similar articles

Cited by

References

    1. Rouchdi Y., El Yassini K., Oufaska K. Resolving Security and Privacy Issues in Radio Frequency Identification Middleware. Int. J. Innov. Sci. Eng. Technol. 2018;5:97–104.
    1. Alizadeh M., Zamani M., Rafiei Shahemabadi A., Shayan J., Azarnik A. A Survey on Attacks in RFID Networks. Open Int. J. Inform. 2012;1:15–24.
    1. Murugan K., Suresh P. Performance Analysis of RSA and Elliptic Curve Cryptography. Int. J. Netw. Secur. 2018;20:15.
    1. Lara-Nino C.A., Diaz-Perez A., Morales-Sandoval M. Elliptic Curve Lightweight Cryptography: A Survey. IEEE Access. 2018;6:72514–72550. doi: 10.1109/ACCESS.2018.2881444. - DOI
    1. Ibrahim A., Dalkılıc G. Review of different classes of RFID authentication protocols. Wirel. Netw. 2019;25:961–974. doi: 10.1007/s11276-017-1638-3. - DOI

LinkOut - more resources