Aim: Internet of Things (IoT) represents a key aspect within several application domains, and it enables growing opportunities for both organizations and end-users. Radio-frequency identification tags are probably the most relevant enabling solution for ubiquitous IoT systems and are often seen as a prerequisite for IoT itself. In this study, we analyzed one of the most promising radio-frequency identification tags to determine whether or not it represents a viable solution for secure IoT applications. Methods: The study was conducted relying on an Android OS application developed within our laboratories, which helped us to inspect the chip and describe its logical data structure. We studied the capabilities of the tag in relation to the application protocol data unit it supports, and we described the cryptographic protocols with which it is equipped. Results: This tag is resistant to forging activities, and it also preserves confidentiality and authenticity on exchanged data. We discussed several known privacy and security patterns that may be addressed relying on the tag we focused on and we underlined some deficiencies concerning chip cloning attack. Again, secure dynamic messaging and mirroring allow the surpassing of several privacy limitations. Conclusion: In this paper we investigated the capabilities of the NT4H2421Gx tag. The deep Android inspection performed on the tag showed that it represents an option to rely on when we need to design secure IoT applications.

Luca Calderoni, D.M. (2020). Forge-resistant radio-frequency identification tags for secure internet of things applications. JOURNAL OF SURVEILLANCE, SECURITY AND SAFETY, 1, 106-118 [10.20517/jsss.2019.01].

Forge-resistant radio-frequency identification tags for secure internet of things applications

Luca Calderoni
Primo
;
Dario Maio;Luciano Margara;
2020

Abstract

Aim: Internet of Things (IoT) represents a key aspect within several application domains, and it enables growing opportunities for both organizations and end-users. Radio-frequency identification tags are probably the most relevant enabling solution for ubiquitous IoT systems and are often seen as a prerequisite for IoT itself. In this study, we analyzed one of the most promising radio-frequency identification tags to determine whether or not it represents a viable solution for secure IoT applications. Methods: The study was conducted relying on an Android OS application developed within our laboratories, which helped us to inspect the chip and describe its logical data structure. We studied the capabilities of the tag in relation to the application protocol data unit it supports, and we described the cryptographic protocols with which it is equipped. Results: This tag is resistant to forging activities, and it also preserves confidentiality and authenticity on exchanged data. We discussed several known privacy and security patterns that may be addressed relying on the tag we focused on and we underlined some deficiencies concerning chip cloning attack. Again, secure dynamic messaging and mirroring allow the surpassing of several privacy limitations. Conclusion: In this paper we investigated the capabilities of the NT4H2421Gx tag. The deep Android inspection performed on the tag showed that it represents an option to rely on when we need to design secure IoT applications.
2020
Luca Calderoni, D.M. (2020). Forge-resistant radio-frequency identification tags for secure internet of things applications. JOURNAL OF SURVEILLANCE, SECURITY AND SAFETY, 1, 106-118 [10.20517/jsss.2019.01].
Luca Calderoni, Dario Maio, Luciano Margara, Luca Spadazzi
File in questo prodotto:
File Dimensione Formato  
3730.pdf

accesso aperto

Tipo: Versione (PDF) editoriale
Licenza: Licenza per Accesso Aperto. Creative Commons Attribuzione (CCBY)
Dimensione 1.54 MB
Formato Adobe PDF
1.54 MB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11585/778859
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact