{"title":"ENHANCING SECURITY OF RFID-ENABLED IOT SUPPLY CHAIN","authors":"H. Turksonmez, M. H. Ozcanhan","doi":"10.22452/mjcs.vol36no3.5","DOIUrl":null,"url":null,"abstract":"In addition to its benefits, the popular Internet of Things (IoT) technology has also opened the way to novel security and privacy issues. The basis of IoT security and privacy starts with trust in the IoT hardware and its supply chain. Counterfeiting, cloning, tampering of hardware, theft, and lost issues in the IoT supply chain have to be addressed, in order to ensure reliable IoT industry growth. In four previous works, radio-frequency identification (RFID)-enabled solutions have been proposed by the same authors, aimed to bring security to the entire IoT supply chain. The works propose a new RFID-traceable hardware architecture, device authentication, and supply chain tracing procedure. In each of these works, a variant of the same is proposed. However, the same variant of lightweight RFID authentication protocol coupled with the offline supply chain proposed in these works has such security vulnerabilities that make the whole supply chain unsafe. In our present work, an online supply chain hop-tracking procedure supported by a novel RFID mutual authentication protocol, based on the strong matching of the RFID readers-their operators-central database present at the transfer hops is proposed. Our proposed Strong RFID Authentication Protocol (STRAP) has been verified by two well-accepted formal protocol analyzers Scyther and AVISPA. The verification results demonstrate that STRAP overcomes the previous works’ vulnerabilities. Furthermore, our proposed novel online supply chain tracing procedure supporting STRAP removes the previous offline supply chain tracing procedure weaknesses.","PeriodicalId":49894,"journal":{"name":"Malaysian Journal of Computer Science","volume":" ","pages":""},"PeriodicalIF":1.1000,"publicationDate":"2023-07-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Malaysian Journal of Computer Science","FirstCategoryId":"94","ListUrlMain":"https://doi.org/10.22452/mjcs.vol36no3.5","RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q4","JCRName":"COMPUTER SCIENCE, ARTIFICIAL INTELLIGENCE","Score":null,"Total":0}
引用次数: 0
Abstract
In addition to its benefits, the popular Internet of Things (IoT) technology has also opened the way to novel security and privacy issues. The basis of IoT security and privacy starts with trust in the IoT hardware and its supply chain. Counterfeiting, cloning, tampering of hardware, theft, and lost issues in the IoT supply chain have to be addressed, in order to ensure reliable IoT industry growth. In four previous works, radio-frequency identification (RFID)-enabled solutions have been proposed by the same authors, aimed to bring security to the entire IoT supply chain. The works propose a new RFID-traceable hardware architecture, device authentication, and supply chain tracing procedure. In each of these works, a variant of the same is proposed. However, the same variant of lightweight RFID authentication protocol coupled with the offline supply chain proposed in these works has such security vulnerabilities that make the whole supply chain unsafe. In our present work, an online supply chain hop-tracking procedure supported by a novel RFID mutual authentication protocol, based on the strong matching of the RFID readers-their operators-central database present at the transfer hops is proposed. Our proposed Strong RFID Authentication Protocol (STRAP) has been verified by two well-accepted formal protocol analyzers Scyther and AVISPA. The verification results demonstrate that STRAP overcomes the previous works’ vulnerabilities. Furthermore, our proposed novel online supply chain tracing procedure supporting STRAP removes the previous offline supply chain tracing procedure weaknesses.
期刊介绍:
The Malaysian Journal of Computer Science (ISSN 0127-9084) is published four times a year in January, April, July and October by the Faculty of Computer Science and Information Technology, University of Malaya, since 1985. Over the years, the journal has gained popularity and the number of paper submissions has increased steadily. The rigorous reviews from the referees have helped in ensuring that the high standard of the journal is maintained. The objectives are to promote exchange of information and knowledge in research work, new inventions/developments of Computer Science and on the use of Information Technology towards the structuring of an information-rich society and to assist the academic staff from local and foreign universities, business and industrial sectors, government departments and academic institutions on publishing research results and studies in Computer Science and Information Technology through a scholarly publication. The journal is being indexed and abstracted by Clarivate Analytics'' Web of Science and Elsevier''s Scopus