Literature DB >> 23659961

A note on the security of IS-RFID, an inpatient medication safety.

Masoumeh Safkhani1, Nasour Bagheri, Majid Naderi.   

Abstract

OBJECTIVE: In this paper we investigate the security level of a comprehensive RFID solution to enhance inpatient medication safety, named IS-RFID, which has been recently proposed by Peris-Lopez et al.
METHOD: We analyses the security of the protocol against the known attacks in the context. The main target of this paper is to determine whether the new protocol provides the confidentiality property, which is expected to be provided by such a protocol.
RESULTS: It was found that IS-RFID has critical weaknesses. The presented security investigations show that a passive adversary can retrieve secret parameters of patient's tag in cost of O(2(16)) off-line PRNG evaluations. Given the tag's secret parameters, any security claims are ruined.
CONCLUSIONS: In this paper we presented an efficient passive secret disclosure attack which retrieves the main secret parameters related to the patient which shows that IS-RFID may put the patient safety on risk. The proposed attacking technique is in light of two vulnerabilities of the protocol: (1) the short length of the used PRNG, which is urged by the target technology, EPC C1 Gen2 ; (2) the message-generating mechanism utilizing PRNG was not carefully scrutinized. While the later point can be fixed by careful designing of the transferred messages between the protocol's party, the earlier point, i.e., the short length of the available PRNG for EPC C1 Gen2 tags, is a limitation which is forced by the technology. In addition, over the last years, schemes based solely on using simple operations or short PRNG (such as IS-RFID) have been shown to offer very low or no security at all. Recent advances in lightweight ciphers, such as PRESENT or Grain , seem a much more appropriate solution rather than relying on short PRNGs. However, such solutions breaks the EPC C1 Gen2 compatibility.
Copyright © 2013 Elsevier Ireland Ltd. All rights reserved.

Entities:  

Keywords:  Authentication; Cryptanalysis; RFID; Secret disclosure

Mesh:

Year:  2013        PMID: 23659961     DOI: 10.1016/j.ijmedinf.2013.04.003

Source DB:  PubMed          Journal:  Int J Med Inform        ISSN: 1386-5056            Impact factor:   4.046


  1 in total

1.  Wireless Sensors Grouping Proofs for Medical Care and Ambient Assisted-Living Deployment.

Authors:  Denis Trček
Journal:  Sensors (Basel)       Date:  2016-01-02       Impact factor: 3.576

  1 in total

北京卡尤迪生物科技股份有限公司 © 2022-2023.