English

Vulnerability Analysis of PAP for RFID Tags

Cryptography and Security 2010-08-24 v1

Abstract

In this paper, we analyze the security of an RFID authentication protocol proposed by Liu and Bailey [1], called Privacy and Authentication Protocol (PAP), and show its vulnerabilities and faulty assumptions. PAP is a privacy and authentication protocol designed for passive tags. The authors claim that the protocol, being resistant to commonly assumed attacks, requires little computation and provides privacy protection and authentication. Nevertheless, we propose two traceability attacks and an impersonation attack, in which the revealing of secret information (i.e., secret key and static identifier) shared between the tag and the reader is unnecessary. Moreover, we review all basic assumptions on which the design of the protocol resides, and show how many of them are incorrect and are contrary to the common assumptions in RFID systems.

Keywords

Cite

@article{arxiv.1008.3625,
  title  = {Vulnerability Analysis of PAP for RFID Tags},
  author = {Mu'awya Naser and Pedro Peris-Lopez and Mohammd Rafie and Jan van der Lubbe},
  journal= {arXiv preprint arXiv:1008.3625},
  year   = {2010}
}

Comments

18 pages, 4 figures

R2 v1 2026-06-21T16:03:34.971Z