Title :
RFID systems integrated OTP security authentication design
Author :
Chao-Hsi Huang ; Shih-Chih Huang
Author_Institution :
Inst. of Comput. Sci. & Inf. Eng., Nat. Ilan Univ., Ilan, Taiwan
fDate :
Oct. 29 2013-Nov. 1 2013
Abstract :
As radio frequency identification (RFID) technology matures, the application of RFID system also increased significantly and has been widely used in commodity storage, access management. We believe that it will become one of the major electronic money for the daily business consumption in the future. However, the stability and security of the data transaction will be more important for the demand of business applications. In the existed solution, we have not yet found an effective way that the Tag can be completely prevented forgery and attack. In this paper, we analyses the security problem of RFID authentication and propose security authentication for RFID tags based on a one-time password (OTP) authentication method. By the way of OTP authentication, we can improve the security of the RFID tag authentication. It can identify the authorized RFID Tag by additional OTP authentication. If an attacker uses eavesdropping to clone a RFID tag, the clone one can be identified by OTP authentication. We use RFC-6238 Time-Based One-Time password (TOTP) algorithm which is based on HMAC-SHA1 algorithm to enhance the authentication mechanism of RFID security. And we also use the computing power of NFC-enabled smart phone to generate TOTP by OTP generator which designed in this paper. The TOTP can be repeated and the security written to the tag. Thought using RADIUS authentication technology, manufacturers can easily apply this technology in the existing RFID system. It is easily provided to users to use roaming function between the different service providers, as long as they using the same frequency and standard of RFID technology.
Keywords :
cryptographic protocols; near-field communication; radiofrequency identification; smart phones; telecommunication security; NFC enabled smart phone; OTP security authentication design; RFID systems; business applications; data transaction; one time password authentication method; radio frequency identification; time based one time password algorithm; Authentication; Certification; Encryption; Generators; RFID tags;
Conference_Titel :
Signal and Information Processing Association Annual Summit and Conference (APSIPA), 2013 Asia-Pacific
Conference_Location :
Kaohsiung
DOI :
10.1109/APSIPA.2013.6694342