- Computer Networks Journal
- June 2010
Digital Object Identifier (DOI)
International Standard Serial Number (ISSN)
Electronic International Standard Serial Number (EISSN)
In RFIDSec'08, Song proposed an ownership transfer scheme, which consists of an ownership transfer protocol and a secret update protocol . The ownership transfer protocol is completely based on a mutual
authentication protocol proposed in WiSec'08 . In Rizomiliotis et al.
(2009) , van Deursen and Radomirovic (2008), the first weaknesses to
be identified (tag and server impersonation) were addressed and this
paper completes the consideration of them all. We find that the mutual
authentication protocol, and therefore the ownership transfer protocol,
possesses certain weaknesses related to most of the security properties
initially required in protocol design: tag information leakage, tag
location tracking, and forward traceability. Moreover, the secret update
protocol is not immune to de-synchronization attacks.