Recently, system designers, especially in the field of product life-cycle management system start considering use of user memory bank of UHF RFID tags. By storing most useful life-cycle data onto a tag, user can access to the data even without access to back-end databases. One of the major issues to make use of the user memory bank is detection of memory tampering. Although technology vendors start introducing new functionalities such as fine grained locking along with high capacity user memory, these tags with new functionalities require new non-standardized air protocol to operate - require modified version of reader/writers. Also, these tags are usually more expensive. In this paper, we introduce a novel approach to this problem: tag side write journaling mechanism and "Tag memory cloaking," which protect the journal by using. Tag private memory region, which is only readable and not writable from external devices such as a reader/writer, but writable by tag itself. Also, any write to the user memory automatically add journal entry - offset and length of the write - into the tag private memory region. Later, a user can check existence of overlapped writes to user memory by checking the journal records. Since we have not modified any of air protocol, standard compliant read/writer can fully capable of all of our proposed operations: write to the tag, read, then detect unusual modification to user memory area. We have implemented the functionality to programmable battery assisted passive tag (BAP), then validated the method with several standard compliant reader/writers.
[1]
Tassos Dimitriou,et al.
A Lightweight RFID Protocol to protect against Traceability and Cloning attacks
,
2005,
First International Conference on Security and Privacy for Emerging Areas in Communications Networks (SECURECOMM'05).
[2]
J. Boyd.
Here comes the wallet phone [wireless credit card]
,
2005,
IEEE Spectrum.
[3]
Simson L. Garfinkel,et al.
RFID privacy: an overview of problems and proposed solutions
,
2005,
IEEE Security & Privacy Magazine.
[4]
Mark Harrison,et al.
Data Synchronization Specification
,
2006
.
[5]
V. Potdar,et al.
Recovering and Restoring Tampered RFID Data using Steganographic Principles
,
2006,
2006 IEEE International Conference on Industrial Technology.
[6]
Ari Juels,et al.
RFID security and privacy: a research survey
,
2006,
IEEE Journal on Selected Areas in Communications.
[7]
Philippe Oechslin,et al.
RFID Traceability: A Multilayer Problem
,
2005,
Financial Cryptography.
[8]
V. Potdar,et al.
Tamper Detection in RFID Tags using Fragile Watermarking
,
2006,
2006 IEEE International Conference on Industrial Technology.