首页> 外文期刊>Vehicular Communications >RSEAP2: An enhanced version of RSEAP, an RFID based authentication protocol for vehicular cloud computing
【24h】

RSEAP2: An enhanced version of RSEAP, an RFID based authentication protocol for vehicular cloud computing

机译:RSEAP2:RSEAP的增强版本,基于RFID的车辆云计算的认证协议

获取原文
获取原文并翻译 | 示例
           

摘要

RSEAP is a recently proposed RFID based authentication protocol for vehicular cloud computing whose authors claimed to be secure and efficient. In this article, we challenge these claims. More precisely, we show that RSEAP does not provide the desired security, and it is possible to conduct both tag and reader impersonation attacks efficiently. Besides, despite the use of timestamps, we show how this protocol also suffers from a range of relay attacks. The complexity of any of the proposed attacks is negligible while the success probability is maximum (i.e., the adversary's success probability is '1' since all the proposed attacks are deterministic). To improve the security of RSEAP scheme, we suggest the required patches for fixing the security vulnerabilities mentioned above. We show that the improved protocol, called RSEAP2, is more efficient (computation and communication costs) than the original RSEAP, while provides a higher security level. The security of RSEAP2 is evaluated informally and also formally using the Scyther tool, which is a well-known and automated tool to assess the security of cryptographic protocols. Additionally, we have formally verified the security of the proposed scheme under the Real-or-Random oracle model. (C) 2020 Elsevier Inc. All rights reserved.
机译:RSEAP是最近提出的基于RFID的车辆云计算认证协议,其作者声称安全有效。在本文中,我们挑战这些索赔。更准确地说,我们表明RSEAP不提供所需的安全性,并且可以有效地进行标签和读者模拟攻击。此外,尽管使用时间戳,但我们展示了该协议的侵占方式如何遭受一系列继电器攻击。所有拟议攻击的复杂性可以忽略不计,同时成功概率最大值(即,敌对的成功概率为“1”,因为所有提议的攻击都是确定性的)。为了提高RSEAP方案的安全性,我们建议修复上述安全漏洞所需的修补程序。我们表明,改进的协议,称为RSEAP2,比原始RSEAP更有效(计算和通信成本),而提供更高的安全级别。 RSEAP2的安全性是非正式地评估的,也可以正式使用SCYTHER工具进行评估,这是一个众所周知的和自动化的工具,以评估加密协议的安全性。此外,我们在实际或随机的Oracle模型下正式验证了所提出的方案的安全性。 (c)2020 Elsevier Inc.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号