3rd International ICST Conference on Security and Privacy in Communication Networks

Breaking EMAP

    Year: 2008
Mihály Bárász, Balázs Boros, Péter Ligeti, Krisztina Lója, Dániel A. Nagy
  ELTECRYPT Research Group, Department of Computer Science, Eötvös University 1117 Budapest, Pázmány Péter sétány 1/c, Hungary
  Department of Telecommunications and Telematics, Budapest University of Technology and Economy 1117 Budapest, Magyar Tudósok krt. 2, Hungary
We have broken EMAP (Efficient Mutual Authentication Protocol), which is a mutual authentication protocol between RFID tags and RFID readers. We give an algorithm, which breaks the protocol after eavesdropping only a few rounds. Assuming that one can eavesdrop a few consecutive rounds of authentications for the same RFID tag (the expected number for the presented algorithm is about 9, but it is possible to reduce this number to about 3.5), the attacker learns the identity number of the tag and every common secret shared by the tag and the reader. This means that in future authentication rounds, the attacker can successfully impersonate the targeted tag. Our breaking procedure is fully passive as opposed to the active attack described in [2].