论文标题

RF-Rherthm:安全可用的两因素RFID身份验证

RF-Rhythm: Secure and Usable Two-Factor RFID Authentication

论文作者

Li, Jiawei, Wang, Chuyu, Li, Ang, Han, Dianqi, Zhang, Yan, Zuo, Jinhang, Zhang, Rui, Xie, Lei, Zhang, Yanchao

论文摘要

被动RFID技术被广泛用于用户身份验证和访问控制中。我们提出了RF-RHILTHM,这是一种安全可用的两因素RFID身份验证系统,对丢失/被盗/克隆的RFID卡具有很强的韧性。在RF-RHILTHM中,每个合法的用户都根据自我选择的秘密旋律在其RFID卡上执行一系列水龙头。这种节奏的抽头可以诱导反向散射信号中的相变,RFID读取器可以检测到以恢复用户的敲击节奏。除了像往常一样验证RFID卡的标识信息外,后端服务器还将提取的敲击节奏与在用户注册阶段中获取的节奏进行了比较。用户通过身份验证检查是否以及两种验证成功。我们还提出了一种新颖的相跳式协议,其中RFID读取器以随机相发出连续波(CW),用于提取用户的秘密攻击节奏。我们的协议可以防止有能力的对手提取,然后从嗅觉的RFID信号中重播合法的敲击节奏。全面的用户实验证实了RF-Rhythm的高度安全性和可用性接近零。

Passive RFID technology is widely used in user authentication and access control. We propose RF-Rhythm, a secure and usable two-factor RFID authentication system with strong resilience to lost/stolen/cloned RFID cards. In RF-Rhythm, each legitimate user performs a sequence of taps on his/her RFID card according to a self-chosen secret melody. Such rhythmic taps can induce phase changes in the backscattered signals, which the RFID reader can detect to recover the user's tapping rhythm. In addition to verifying the RFID card's identification information as usual, the backend server compares the extracted tapping rhythm with what it acquires in the user enrollment phase. The user passes authentication checks if and only if both verifications succeed. We also propose a novel phase-hopping protocol in which the RFID reader emits Continuous Wave (CW) with random phases for extracting the user's secret tapping rhythm. Our protocol can prevent a capable adversary from extracting and then replaying a legitimate tapping rhythm from sniffed RFID signals. Comprehensive user experiments confirm the high security and usability of RF-Rhythm with false-positive and false-negative rates close to zero.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源