首页> 外文会议>International Conference on Financial Cryptography and Data Security >Reverse Fuzzy Extractors: Enabling Lightweight Mutual Authentication for PUF-Enabled RFIDs
【24h】

Reverse Fuzzy Extractors: Enabling Lightweight Mutual Authentication for PUF-Enabled RFIDs

机译:反向模糊提取器:为支持PUF的RFID启用轻量级相互身份验证

获取原文

摘要

RFID-based tokens are increasingly used in electronic payment and ticketing systems for mutual authentication of tickets and terminals. These systems typically use cost-effective tokens without expensive hardware protection mechanisms and are exposed to hardware attacks that copy and maliciously modify tokens. Physically Unclonable Functions (PUFs) are a promising technology to protect against such attacks by binding security critical data to the physical characteristics of the underlying hardware. However, existing PUF-based authentication schemes for RFID do not support mutual authentication, are often vulnerable to emulation and denial-of service attacks, and allow only for a limited number of authentications. In this paper, we present a new PUF-based authentication scheme that overcomes these drawbacks: it supports PUF-based mutual authentication between tokens and readers, is resistant to emulation attacks, and supports an unlimited number of authentications without requiring the reader to store a large number of PUF challenge/response pairs. In this context, we introduce reverse fuzzy extractors, a new approach to correct noise in PUF responses that allows for extremely lightweight implementations on the token. Our proof-of-concept implementation shows that our scheme is suitable for resource-constrained devices.
机译:基于RFID的令牌越来越多地用于电子支付和票务系统,用于相互认证的门票和终端。这些系统通常使用具有昂贵的硬件保护机制的经济高效的令牌,并且暴露于复制和恶意修改令牌的硬件攻击。物理不可渗透的功能(PUF)是一种希望通过将安全性关键数据绑定到基础硬件的物理特征来保护此类攻击的有希望的技术。但是,RFID的现有基于PUF的身份验证方案不支持相互身份验证,通常容易受到仿真和拒绝服务攻击,并且仅允许有限数量的身份验证。在本文中,我们介绍了一种新的基于PUF的身份验证方案,克服了这些缺点:它支持令牌和读取器之间的基于PUF的相互认证,对仿真攻击有抵抗,并且不需要读者存储无限数量的身份情况大量的PUF挑战/回复对。在此上下文中,我们介绍了反向模糊提取器,这是一种纠正PUF响应中噪声的新方法,允许在令牌上实现极其轻量级的实现。我们的概念证明表明我们的计划适用于资源受限设备。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号