关键词:
Internet of Things (IoT)
Radio Frequency Identification (RFID)
Privacy-preserving
Lightweight authentication
摘要:
The rapid growth of the Internet of Things (IoT for short) has expanded its applications across diverse domains, including smart healthcare, smart homes, and smart factories. Among the key technologies driving this evolution, Radio Frequency Identification (RFID for short) plays a pivotal role in IoT ecosystems due to its automation, identity recognition, and portability attributes. These features make RFID essential for simplifying device management and enhancing traceability in practical scenarios, particularly in healthcare, where it optimizes the management of patient medical records. However, frequent information exchanges within RFID systems pose a significant challenge, as inadequate authentication mechanisms can lead to unintended exposure of sensitive personal data. Fan et al. propose a lightweight RFID authentication protocol in IEEE Transactions on Industrial Informatics to address this issue. Unfortunately, our analysis finds several security vulnerabilities in their protocol, including susceptibility to impersonation, traceability, and secret disclosure attacks. In this paper, we develop a new lightweight privacy-protection RFID protocol, building upon Fan et al.'s framework. Our security evaluation demonstrates that the proposed protocol effectively mitigates these threats, ensuring the confidentiality and integrity of sensitive data in RFID-enabled systems.