首页> 外文会议>Computer security - ESORICS 2010 >Readers Behaving Badly Reader Revocation in PKI-Based RFID Systems
【24h】

Readers Behaving Badly Reader Revocation in PKI-Based RFID Systems

机译:在基于PKI的RFID系统中,读取器的读取器性能很差

获取原文
获取原文并翻译 | 示例

摘要

Recent emergence of RFID tags capable of performing public key operations motivates new RFID applications, including electronic travel documents, identification cards and payment instruments. In this context, public key certificates form the cornerstone of the overall system security. In this paper, we argue that one of the prominent challenges is how to handle revocation and expiration checking of RFID reader certificates. This is an important issue considering that these high-end RFID tags are geared for applications such as e-documents and contactless payment instruments. Furthermore, the problem is unique to public key-based RFID systems, since a passive RFID tag has no clock and thus cannot use (time-based) off-line methods. In this paper, we address the problem of reader certificate expiration and revocation in PKI-Based RFID systems. We begin by observing an important distinguishing feature of personal RFID tags used in authentication, access control or payment applications - the involvement of a human user. We take advantage of the user's awareness and presence to construct a simple, efficient, secure and (most importantly) feasible solution. We evaluate the usability and practical security of our solution via user studies and discuss its feasibility.
机译:能够执行公钥操作的RFID标签的最新出现激发了新的RFID应用,包括电子旅行证件,身份证和支付工具。在这种情况下,公钥证书构成了整个系统安全性的基石。在本文中,我们认为最大的挑战之一是如何处理RFID读取器证书的吊销和到期检查。考虑到这些高端RFID标签适用于电子文档和非接触式支付工具等应用,这是一个重要的问题。此外,该问题对于基于公钥的RFID系统是唯一的,因为无源RFID标签没有时钟,因此无法使用(基于时间的)离线方法。在本文中,我们解决了基于PKI的RFID系统中读者证书过期和吊销的问题。我们首先观察用于身份验证,访问控制或支付应用程序的个人RFID标签的重要区别特征-人类用户的参与。我们利用用户的意识和存在来构建一个简单,有效,安全和(最重要的)可行的解决方案。我们通过用户研究评估我们解决方案的可用性和实际安全性,并讨论其可行性。

著录项

  • 来源
    《Computer security - ESORICS 2010》|2010年|p.19-36|共18页
  • 会议地点 Athens(GR);Athens(GR)
  • 作者单位

    Computer Science Department University of California Irvine, CA 92697;

    Computer Science Department University of California Irvine, CA 92697;

    Computer Science Department University of California Irvine, CA 92697;

  • 会议组织
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 安全保密;
  • 关键词

  • 入库时间 2022-08-26 13:47:59

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号