RFID眾多應用中,愈來愈受到矚目的技術之一為所有權移轉,藉由更改標籤內金鑰而達到所有權的移轉。所有權的更替所代表的是標籤在不同擁有者之間移轉,舊擁有者不再對標籤有任何管控的權限,取而代之的是新擁有者對標籤的掌控。所有權移轉可應用在電子商務或物流管理上,舊擁有者在將貼有標籤之物品移轉給新擁有者之後,也一併將標籤的所有權也移轉,而新的擁有者便可利用RFID標籤進行快速且大量的物流管理。在這樣日益廣泛的應用中,相關的認證協定也面臨資訊安全的威脅,例如標籤之EPC(electronic product code)被讀出或是標籤位置被追蹤而暴露地點隱私等安全問題。
本研究所探討的類似協定為了達到匿名性而使得伺服器運算成本較高,因此本研究提出一種低運算成本且具匿名性的RFID標籤所有權移轉協定,希望藉此改善安全性上的弱點也降低認證雙方的運算負擔。
In many applications of RFID technology, tag ownership transfer attracts much more attention now. We can modify shared secret key of tag and server to achieve the ownership transfer. After ownership transfer, old owners no longer have any control permissions, replaced by the new owners. RFID tag ownership transfer can be applied to e-commerce or logistics management. The goods which are affixed a RFID tag can be control by logistic system easily. When new owners receive these goods, their logistic system can obtain information of goods quickly. But the related authentication protocols are facing the threat of information security, such as the EPC (electronic product code) of tag be leaked, tag position be traced or other security issues.
This study proposes a low computational cost RFID tags ownership transfer and possess tag anonymity simultaneously, hoping to reduce both the security weaknesses and computational burden.