LIGHTWEIGHT RFID MUTUAL AUTHENTICATION PROVIDING UNTRACEABILITY
DOI:
https://doi.org/10.52326/jes.utm.2026.33(2).06Keywords:
attack, traceability, computer security, cryptography, privacy, protocol, RFID systemAbstract
The widespread deployment of low-cost RFID tags raises significant security and privacy concerns, since tags with limited computational resources cannot support strong cryptographic primitives, while backward and forward untraceability have become essential requirements for modern RFID protocols. We hypothesize that a lightweight authentication scheme based on pseudo-random number generators (PRNGs) and short-term session keys can provide a broad spectrum of security properties without relying on costly primitives. The purpose of this study is to design and analyze such a mutual authentication protocol for RFID systems. Two variants of the protocol are constructed - one optimized for limited tag computational power and one minimizing data transmission - using one-time pad encryption keyed by PRNG output, timestamps for replay-attack protection, and a refreshable forward/backward key sub-chain. The resulting protocol withstands replay, denial-of-service, tag and server impersonation attacks, and guarantees information privacy, location privacy, and both backward and forward untraceability. We conclude that even weak primitives such as linear or non-linear feedback shift registers can be safely used as the underlying PRNG, which makes the protocol particularly well suited to low-cost RFID deployments.
References
Batina L, Guajardo J, Kerins T, et al (2006) An elliptic curve processor suitable for RFID tags. https://www.researchgate.net/publication/220337092_An_elliptic_curve_processor_suitable_for_RFID-tags. Accessed 16 April 2026
Batina L, Guajardo J, Kerins T, et al (2007) Public-key cryptography for RFID-tags. In: Proceedings of the Fifth IEEE International Conference on Pervasive Computing and Communications Workshops. pp 217–222
Lee YK, Sakiyama K, Batina L, Verbauwhede I (2008) Elliptic-curve-based security processor for RFID. IEEE Trans Comput 57:1514–1527. https://doi.org/10.1109/TC.2008.148
Feldhofer M, Dominikus S, Wolkerstorfer J (2004) Strong authentication for RFID systems using the AES algorithm. In: Joye M, Quisquater J-J (eds) Cryptographic Hardware and Embedded Systems – CHES. Lecture Notes in Computer Science, vol 3156. Springer, pp 357–370
Ţiplea FL, Andriesei C, Hristea C (2020) Security and privacy of PUF-based RFID systems. In: Cryptography - Recent Advances and Future Developments. IntechOpen, London, pp 1–23. https://doi.org/10.5772/intechopen.94018
Ţiplea FL, Hristea C (2021) Practically efficient RFID scheme with constant-time identification. In: Proceedings of the 18th International Conference on Security and Cryptography (SECRYPT), Vol. 1. SciTePress, pp 495–506. https://doi.org/10.5220/0010544804950506
Ţiplea FL, Hristea C (2021) PUF protected variables: a solution to RFID security and privacy under corruption with temporary state disclosure. IEEE Trans Inf Forensics Secur 16:999–1013. https://doi.org/10.1109/TIFS.2020.3027147
Hristea C, Ţiplea FL (2020) Privacy of stateful RFID systems with constant tag identifiers. IEEE Trans Inf Forensics Secur 15:1920–1934. https://doi.org/10.1109/TIFS.2019.2953398
Ţiplea FL (2022) Narrow privacy and desynchronization in Vaudenay’s RFID model. Int J Inf Secur 21:563– 575. https://doi.org/10.1007/s10207-021-00569-0
Pantelić G, Bojanić S, Tomašević V (2009) Authentication protocols in RFID systems. In: Zhang Y, Kitsos P (eds) Security in RFID and Sensor Networks. Auerbach Publications, pp 99–120
Avoine G, Oechslin P (2005) A scalable and provably secure hash-based RFID protocol. In: Third IEEE International Conference on Pervasive Computing and Communications Workshops. pp 110–114
Henrici D, Muller P (2004) Hash-based enhancement of location privacy for radio-frequency identification devices using varying identifiers. In: Proceedings of the Second IEEE Annual Conference on Pervasive Computing and Communications Workshops. pp 149–153
Ohkubo M, Suzuki K, Kinoshita S (2003) Cryptographic approach to “privacy-friendly” tags. In: RFID Privacy Workshop.https://www.researchgate.net/publication/2926255_Cryptographic_Approach_to_PrivacyFriendly_Tags. Accessed 16 April 2026
Lim CH, Kwon T (2006) Strong and robust RFID authentication enabling perfect ownership transfer. In: Ning P, Qing S, Li N (eds) Information and Communications Security. Lecture Notes in Computer Science, vol 4307. Springer, pp 1–20
Song B, Mitchell CJ (2008) RFID authentication protocol for low-cost tags. In: Proceedings of the First ACM Conference on Wireless Network Security. pp 140–147
Weis SA, Sarma SE, Rivest RL, Engels DW (2004) Security and privacy aspects of low-cost radio frequency identification systems. In: Hutter D, Müller G, Stephan W, Ullmann M (eds) Security in Pervasive Computing. Lecture Notes in Computer Science, vol 2802. Springer, pp 201–212
Peris-Lopez P, Hernandez-Castro JC, Estevez-Tapiador JM, Ribagorda A (2006) EMAP: an efficient mutualauthentication protocol for low-cost RFID tags. In: Meersman R, Tari Z, Herrero P (eds) On the Move to Meaningful Internet Systems. Lecture Notes in Computer Science, vol 4277. Springer, pp 352–361
Peris-Lopez P, Hernandez-Castro JC, Estevez-Tapiador JM, Ribagorda A (2006) M2AP: a minimalist mutualauthentication protocol for low-cost RFID tags. In: Ma J, Jin H, Yang LT, Tsai JJ-P (eds) Ubiquitous Intelligence and Computing. Lecture Notes in Computer Science, vol 4159. Springer, pp 912–923
Peris-Lopez P, Hernandez-Castro JC, Estevez-Tapiador JM, Ribagorda A (2009) Advances in ultralightweight cryptography for low-cost RFID tags: Gossamer protocol. In: Chung K-I, Sohn K, Yung M (eds) Information Security Applications. Springer, pp 56–68
Juels A (2005) Minimalist cryptography for low-cost RFID tags (extended abstract). In: Blundo C, Cimato S (eds) Security in Communication Networks. Lecture Notes in Computer Science, vol 3352. Springer, pp 149– 164
Juels A, Weis SA (2005) Authenticating pervasive devices with human protocols. In: Shoup V (ed) Advances in Cryptology – CRYPTO. Lecture Notes in Computer Science, vol 3621. Springer, pp 293–308
Vajda I, Buttyán L (2003) Lightweight authentication protocols for low-cost RFID tags. In: Second Workshop on Security in Ubiquitous Computing – Ubicomp 2003. https://www.researchgate.net/publication/2930099_Lightweight_Authentication_Protocols_for_LowCost_RFID_Tags. Accessed 16 April 2026
Chander B, Gopalakrishnan K (2022) A secured and lightweight RFID-tag based authentication protocol with privacy-preserving in telecare medicine information system. Comput Commun 191:425–437. https://doi.org/10.1016/j.comcom.2022.05.002
Khorasgani AA, Sajadieh M, Yazdani MR (2022) Novel lightweight RFID authentication protocols for inexpensive tags. J Inf Secur Appl 67:103191. https://doi.org/10.1016/j.jisa.2022.103191
Kumar S, Banka H, Kaushik B, Sharma S (2021) A review and analysis of secure and lightweight ECC-based RFID authentication protocol for internet of vehicles. Trans Emerg Telecommun Technol 32:e4354. https://doi.org/10.1002/ett.4354
Mala H, Aghili SF (2019) Security analysis of an ultra-lightweight RFID authentication protocol for mcommerce. Int J Commun Syst 32:e3837. https://doi.org/10.1002/dac.3837
Xiao L, Xu H, Zhu F, et al (2020) SKINNY-based RFID lightweight authentication protocol. Sensors 20:1366. https://doi.org/10.3390/s20051366
Alavi SM, Baghery K, Abdolmaleki B, Aref MR (2015) Traceability analysis of recent RFID authentication protocols. Wirel Pers Commun 83:1663–1682. https://doi.org/10.1007/s11277-015-2469-0
Chien HY, Huang CW (2007) Security of ultra-lightweight RFID authentication protocols and its improvements. SIGOPS Oper Syst Rev 41:83–86
Chien HY, Huang CW (2010) A lightweight authentication protocol for low-cost RFID. J Signal Process Syst 59:95–102
Piramuthu S (2007) Protocols for RFID tag/reader authentication. Decis Support Syst 43:897–914. https://doi.org/10.1016/j.dss.2007.01.003
Hermans J, Peeters R, Preneel B (2014) Proper RFID privacy: model and protocols. IEEE Trans Mob Comput 13:2888–2902. https://doi.org/10.1109/TMC.2014.2314127
Vaudenay S (2007) On privacy models for RFID. In: Proceedings of the Advances in Cryptology 13th International Conference on Theory and Application of Cryptology and Information Security, ASIACRYPT. Springer, Berlin, Heidelberg, pp 68–87
Ţiplea FL, Hristea C, Bulai R (2022) Privacy and reader-first authentication in Vaudenay’s RFID model with temporary state disclosure. Comput Sci J Moldova 30(3):335–359
Burmester M, De Medeiros B (2008) The security of EPC Gen2 compliant RFID protocols. In: Proceedings of the 6th International Conference on Applied Cryptography and Network Security. Springer, Berlin, Heidelberg, pp 490–506
Ţiplea FL (2014) A lightweight authentication protocol for RFID. In: Kotulski Z, Ksiezopolski B, Mazur K (eds) Cryptography and Security Systems – Third International Conference. Communications in Computer and Information Science, vol 448. Springer, pp 110–121
Năstase GD, Ţiplea FL (2015) On a lightweight authentication protocol for RFID. In: Bica I, Naccache D, Simion E (eds) Innovative Security Solutions for Information Technology and Communications – SECITC. Lecture Notes in Computer Science, vol 9522. Springer, pp 212–225
Molnar D, Wagner D (2004) Privacy and security in library RFID: issues, practices, and architectures. In: Proceedings of the 11th ACM Conference on Computer and Communications Security. pp 210–219
Dimitriou T (2005) A lightweight RFID protocol to protect against traceability and cloning attacks. In: First International Conference on Security and Privacy for Emerging Areas in Communications Networks. pp 59– 66
Chien HY, Chen CH (2007) Mutual authentication protocol for RFID conforming to EPC Class 1 Generation 2 standards. Comput Stand Interfaces 29:254–259. https://doi.org/10.1016/j.csi.2006.04.003
Weis SA (2003) Security and privacy in radio-frequency identification devices. MS Thesis, Massachusetts Institute of Technology, Cambridge, MA
Duc DN, Park J, Lee H, Kim K (2006) Enhancing security of EPCglobal Gen-2 RFID tag against traceability and cloning. In: Proc SCIS, Hiroshima, Japan. p 97
Yeh KH, Lo NW (2010) Improvement of two lightweight RFID authentication protocols. Inf Assur Secur Lett 1:6–11. https://www.mirlabs.org/iasl/volume_1/IASL_Vol_1_Paper_2.pdf. Accessed 16 April 2026
Zhang Y, Kitsos P (2009) Security in RFID and Sensor Networks, 1st edn. Auerbach Publications, Boston. https://www.researchgate.net/publication/326990799_Security_in_RFID_and_sensor_networks. Accessed 16 April 2026
Downloads
Published
How to Cite
License
Copyright (c) 2026 JOURNAL OF ENGINEERING SCIENCE

This work is licensed under a Creative Commons Attribution 4.0 International License.