Cryptanalysis and Enhancement of a Secure Group Ownership Transfer Protocol for RFID Tags

  • Hoda Jannati
  • Abolfazl Falahati
Conference paper
Part of the Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering book series (LNICST, volume 99)


Ownership transfer and grouping proof protocols are the two most important requirements for RFID tag in various applications such as pharmaceutical distribution and manufacturing. In 2010, Zuo integrated these two requirements and introduced a protocol for RFID tag group ownership transfer (GOT), i.e., transferring the ownership of a group of tags in one session. However, this paper shows that Zuo’s protocol is vulnerable to de-synchronization attack and tag impersonating in the presence of cheating old owner. This paper also proposes solutions to fix the security flaws of Zuo’s GOT protocol.


de-synchronization attack grouping proof ownership transfer RFID tags 


Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.


  1. 1.
    Finkelzeller, K.: The RFID Handbook, 2nd edn. John Wiley-Sons (2003)Google Scholar
  2. 2.
    Han, D., Kwon, D.: Vulnerability of an RFID Authentication Protocol Conforming to EPC Class 1 Generation 2 Standards. Computer Standards and Interfaces 31(4) (2009)Google Scholar
  3. 3.
    Rizomiliotis, P., Rekleitis, E., Gritzalis, S.: Security Analysis of the Song-Mitchell Authentication Protocol for Low-cost RFID Tags. IEEE Communications Letters 13(4) (2009)Google Scholar
  4. 4.
    Jannati, H., Falahati, A.: Cryptanalysis and Enhancement of two Low Cost RFID Authentication Protocols. International Journal of UbiComp (IJU) 3(1), 1–9 (2012)CrossRefGoogle Scholar
  5. 5.
    Fouladgar, S., Afifi, H.: A Simple Privacy Protecting Scheme Enabling Delegation and Ownership Transfer for RFID Tags. Journal of Communications 2(6), 6–13 (2007)CrossRefGoogle Scholar
  6. 6.
    Chen, C.-L., Chen, Y.-Y., Huang, Y.-C., Liu, C.-S., Lin, C.-I., Shih, T.-F.: Anti-Counterfeit Ownership Transfer Protocol for Low Cost RFID System. WSEAS Transactions on Computers 7(8), 1149–1158 (2008)Google Scholar
  7. 7.
    Kapoor, G., Piramuthu, S.: Vulnerabilities in Some Recently Proposed RFID Ownership Transfer Protocols. IEEE Communications Letters 14(3), 260–262 (2010)CrossRefGoogle Scholar
  8. 8.
    Alaraj, A.-M.: Ownership Transfer Protocol. In: IEEE International Conference for Internet Technology and Secured Transactions (ICITST 2010), pp. 1–6 (2010)Google Scholar
  9. 9.
    Li, T., Jin, Z., Pang, C.: Secured Ownership Transfer Scheme for Low-Cost RFID Tags. In: IEEE International Conference on Intelligent Networks and Intelligent Systems (ICINIS 2010), pp. 584–587 (2010)Google Scholar
  10. 10.
    Juels, A.: Yoking proofs for RFID Tags. In: Second IEEE Annual Conference on Pervasive Computing and Communications Workshops, Washington, DC, USA, pp. 138–143 (2004)Google Scholar
  11. 11.
    Chien, H.-Y., Liu, S.-B.: Tree-based RFID yoking proof. In: IEEE International Conference on Networks Security, Wireless Communications and Trusted Computing (NSWCTC 2009), pp. 550–553 (2009)Google Scholar
  12. 12.
    Lopez, P.-P., Orfila, A., Castro, J.-C.-H., van der Lubbe, J.-C.-A.: Flaws on RFID Grouping-Proofs, Guidelines for Future Sound Protocols. Journal of Network and Computer Applications 34(3) (2011)Google Scholar
  13. 13.
    Yu, Y.-C., Hou, T.-W., Chiang, T.-C.: Low Cost RFID Real Lightweight Binding Proof Protocol for Medication Errors and Patient Safety. Journal of Medical Systems (2010), doi:10.1007/s10916-010-9546-4Google Scholar
  14. 14.
    Zuo, Y.: Changing Hands Together: A Secure Group Ownership Transfer Protocol for RFID Tags. In: The 43rd IEEE Hawaii International Conference on System Sciences (HICSS 2010), Honolulu, HI, pp. 1–10 (2010)Google Scholar

Copyright information

© ICST Institute for Computer Science, Social Informatics and Telecommunications Engineering 2012

Authors and Affiliations

  • Hoda Jannati
    • 1
  • Abolfazl Falahati
    • 1
  1. 1.Department of Electrical Engineering (DCCS Lab)Iran University of Science and TechnologyTehranIran

Personalised recommendations