User-aided reader revocation in PKI-based RFID systems

被引:3
作者
Nithyanand, Rishab [1 ]
Tsudik, Gene [2 ]
Uzun, Ersin [3 ]
机构
[1] SUNY Stony Brook, Stony Brook, NY USA
[2] Univ Calif Irvine, Irvine, CA USA
[3] Palo Alto Res Ctr, 3333 Coyote Hill Rd, Palo Alto, CA 94304 USA
关键词
RFID; privacy; security; usability;
D O I
10.3233/JCS-2011-0435
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recent emergence of RFID tags capable of performing public key operations motivates new RFID applications, including electronic travel documents, identification cards and payment instruments. In this context, public key certificates form the cornerstone of the overall system security. In this paper, we argue that one of the prominent challenges is how to handle revocation and expiration checking of RFID reader certificates. This is an important issue considering that these high-end RFID tags are geared for applications such as e-documents and contactless payment instruments. Furthermore, the problem is unique to public key-based RFID systems, since a passive RFID tag has no clock and thus cannot use (time-based) off-line methods. In this paper, we address the problem of reader certificate expiration and revocation in PKI-based RFID systems. We begin by observing an important distinguishing feature of personal RFID tags used in authentication, access control or payment applications - the involvement of a human user. We take advantage of the user's awareness and presence to construct a simple, efficient, secure and (most importantly) feasible solution. We evaluate the usability and practical security of our solution via user studies and discuss its feasibility.
引用
收藏
页码:1147 / 1172
页数:26
相关论文
共 38 条
[1]  
[Anonymous], 1999, 2459 RFC
[2]   An empirical evaluation of the System Usability Scale [J].
Bangor, Aaron ;
Kortum, Philip T. ;
Miller, James T. .
INTERNATIONAL JOURNAL OF HUMAN-COMPUTER INTERACTION, 2008, 24 (06) :574-594
[3]  
Blundo C., 2008, C RFID SEC BUD HUNG
[4]   Effects of Different Viewing Perspectives on Somatosensory Activations During Observation of Touch [J].
Schaefer, Michael ;
Xu, Benjamin ;
Flor, Herta ;
Cohen, Leonardo G. .
HUMAN BRAIN MAPPING, 2009, 30 (09) :2722-2730
[5]  
Bundesamt fur Sicherheit in der Informationstechnik, 2018, ANGR KAMP GEG ENERGI
[6]  
Cheon J.H., 2009, 2009092 CRYPT EPRINT
[7]  
Czeskis A., 2008, C COMP COMM SEC CCS
[8]  
Goodrich M., 2003, US Patent Appl, Patent No. [10/416,015, 10416015]
[9]  
Heydt-Benjamin T., 2007, C FIN CRYPT DAT SEC
[10]  
Hoepman JH, 2006, LECT NOTES COMPUT SC, V4266, P152