BIO-THENTIC CARD: AUTHENTICATION CONCEPT FOR RFID CARD
Ikuesan Richard Adeyemi
Dept. computer science and information system
Universiti Teknologi, MalaysiaJohor Bahru, Malaysia
Norafida Bt, Ithnin
Dept. computer science and information system
Universiti Teknologi, MalaysiaJohor Bahru, Malaysia
Abstract
Radio frequency identification (RFID) is a technology thatemploys basic identifier of an object embedded in a chip,transmitted via radio wave, for identification. An RFID Cardresponds to query/interrogation irrespective of ‘
Who
’ holds theCard; like a key to a door. Since an attacker can possess thecard, access to such object can therefore be easilycompromised. This security breach is classified as anunauthorized use of Card, and it forms the bedrock for RFIDCard compromise especially in access control. As an on-cardauthentication mechanism, this research proposed a concepttermed Bio-Thentic Card, which can be adopted to prevent thissingle point of failure of RFID Card. The Bio-Thentic Card wasfabricated, tested and assessed in line with the known threats,and attacks; and it was observed to proffer substantive solutionto unauthorized use of RFID Card vulnerability.
Key words
: Vulnerability, unauthorized, mitigation,authentication, communication, access control systemI.
INTRODUCTIONRadio frequency identification (RFID) technology is atechnology that has gained wider adoption into the humaneveryday life since its first usage in identification friend or foe(IFF) during the II world war
[1, 3]
. RFID is characterized by itsubiquitous nature, flexibility, mobility and integratability,which has contributed to its adoption in places such as accesscontrol system, conveyor control system, banking notes, itemidentification e.t.c. While RFID pros have greatly improveother technology, its cons has also generated series of securityand privacy challenges
[2, 3, 6]
some to the detriment of thesystem being integrated into
[4, 5]
. However, such challenges arenot limited to only RFID systems, but peculiar to RFIDsystems, are attacks such as relay attack, cloning, clandestinetracking, unauthorized tag read, and unauthorized tag use
[2, 6, 8]
. Un-authorization of card use is a general challenge in accesscontrol system; hence, most systems would require a secondarycontrol mechanism.However, the integration of the RFID tag into access controlCard otherwise known as RFID Card has further complicatedthe challenges in access control cards leading to greater trade-offs in security and privacy
[3, 6,7, 8]
. Access control RFID carddo not provide on-card authentication system hence is openlyvulnerable to attacks that breach the confidentiality of a securedsystem. RFID Card responds to interrogation from an RFIDReader irrespective of ‘
who
’ holds the card, or whether thesubject has the required privilege to do so. This lack of authorization priori to interrogation can be said to be the principal point of failure of the RFID Card. For instance,consider the situation where an unauthorized subject withmalicious intent or the otherwise, gains access to a classifieddata through a stolen RFID Card and consequently jeopardizethe confidentiality of the system under protection. It suffixes tonote that, to the best of our knowledge, no knowncountermeasure addressed this single point of failure of theRFID Card.However, mitigating this critical point of failure is not as trivialas it sounds. Faraday shield model in [1] is popular method(aluminum-foiled wallet for example) of shielding the RFIDCard from unauthorized tag reading, thus enhancing the privacy protection of the RFID tag. The unauthorized tag use as appliedto RFID Card is the main goal of this paper as analyzed in [31].The remaining of this paper is organized as follows. Section IIhighlights the related research works on RFID tag withreference to its physical layer, discusses the principal point of failure of the RFID Card. Section III introduces the conceptused in this study, detailed the design and result of this study.Section IV presents the analysis and the conclusion of thisconcept.II.
RELATED RESEARCHRFID Card is a composition of antenna unit, memory unit, processing unit, and a tag, which communicates with an RFIDReader wirelessly using the near field coupling principle. Over the past decades researchers have worked extensively on theRFID system but interest on RFID on-card authenticationsystem have received minimal attention. According to [4, 9],the physical layer of the RFID system is the perimeter defenseline for security tightening in RFID system. RFIDauthentication protocols
[10, 11, 12, 13, 14]
are designed to mitigatecommunication attacks between the tag and the Reader.Similarly, various lightweight cryptographic protocols andtechniques
[15, 16, 17, 18, 19, 20,]
have also been designed to combatsecurity vulnerabilities in the RFID system. However, theseauthentication practices do not apply to the tag end of the
(IJCSIS) International Journal of Computer Science and Information Security,Vol. 10, No. 7, July 201263http://sites.google.com/site/ijcsis/ISSN 1947-5500