Analysis of block cipher modes of operation for rfid devices
The RFID system consists of radio-tag and interrogator. The main purpose of devices is authentication with a transmission of small amount of data between tag and interrogator. We study modes that require only block encryption to be implemented in the tag (due to hardware limitations). CTR, OFB and modified CBC modes were analyzed. Modified CBC mode CBC[F] can be specified as follows: Co = IV, Ci = Fk (Ci-1 e Mi), where Fk denotes either encryption (Fk = Ek) or decryption (Fk = E-1) of one block of data on the key k, Mi is the i-th block of plaintext, Ci is the i-th block of ciphertext, IV is an initialization vector. Assume that the length of the key is k bits, the length of the one block of data is n bits, and consider an adversary that runs time no more than t, makes no more than q oracle queries, each of length no more than m blocks. Then, given an oracle access to the CBC[Ek] and CbC = CBC[E-1] modes, the maximal advantage in the LOR-experiment can be bounded from above by: LOR LOR , 3q2m2 t + q AdvCBC,CBC (t,q,m) ^ 2n _ qm + 2-1 •
Keywords
доказуемая стойкость, RFID, режим шифрования, provable security, RFID, mode of operationAuthors
Name | Organization | |
Tsaregorodtsev K. D. | M. V. Lomonosov Moscow State University; NPK "Kryptonite" | kirill94_12@mail.ru |
References

Analysis of block cipher modes of operation for rfid devices | Applied Discrete Mathematics. Supplement. 2020. № 13. DOI: 10.17223/2226308X/13/20