vix.ing · top · new · best · stats · spec

Cryptanalysis of the SASI Ultralightweight RFID Authentication Protocol with Modular Rotations

2008/11/26 by Julio Hernández-Castro, Hernandez-Castro, Julio C., Juan Tapiador +5 · 1 citation
Computer Science · Engineering · #Advanced Authentication Protocols Security #Antenna Design and Analysis #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #RFID technology advancements

paper · pdf · doi:10.48550/arxiv.0811.4257

openalex publication_date 2008/11/26 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

In this work we present the first passive attack over the SASI lightweight authentication protocol with modular rotations. This can be used to fully recover the secret ID of the RFID tag, which is the value the protocol is designed to conceal. The attack is described initially for recovering \lfloor log2(96) \rfloor=6 bits of the secret value ID, a result that by itself allows to mount traceability attacks on any given tag. However, the proposed scheme can be extended to obtain any amount of bits of the secret ID, provided a sufficiently large number of successful consecutive sessions are eavesdropped. We also present results on the attack's efficiency, and some ideas to secure this version of the SASI protocol.

Cited by

Related