[Paper Review] An Authentication Protocol Based on Combined RFID-Biometric System RFID-Biometric System
This paper proposes a lightweight RFID-biometric authentication protocol that enhances security and privacy by combining RFID tags with biometric data using a pseudorandom number generator (PRNG), secure hash functions, and a biometric hash function. The protocol ensures mutual authentication, confidentiality, and resistance to common attacks, with formal verification using AVISPA and SPAN tools confirming its security properties.
Radio Frequency Identification (RFID) and biometric technologies saw fast evolutions during the last years and which are used in several applications, such as access control. Among important characteristics in the RFID tags, we mention the limitation of resources (memory, energy, ...). Our work focuses on the design of a RFID authentication protocol which uses biometric data and which confirms the secrecy, the authentication and the privacy. Our protocol requires a PRNG (Pseud-Random Number Generator), a robust hash function and Biometric hash function. The Biometric hash function is used to optimize and to protect biometric data. For Security analysis of protocol proposed, we will use AVISPA and SPAN tools to verify the authentication and the secrecy.
Motivation & Objective
- To address the security and privacy challenges in RFID-based access control systems.
- To design a lightweight authentication protocol suitable for resource-constrained RFID tags.
- To integrate biometric data securely into the authentication process without storing raw biometric templates.
- To ensure mutual authentication, data secrecy, and resistance to impersonation and replay attacks.
- To formally verify the protocol’s security properties using automated tools.
Proposed method
- The protocol uses a Pseudorandom Number Generator (PRNG) to generate session-specific keys.
- A robust cryptographic hash function is employed to ensure data integrity and confidentiality.
- A biometric hash function is applied to transform raw biometric data into a secure, non-invertible template.
- Mutual authentication is achieved through a challenge-response mechanism involving the tag, reader, and a central server.
- The protocol design minimizes computational and memory overhead to suit low-power RFID devices.
- Security properties are formally verified using the AVISPA and SPAN tools to analyze authentication and secrecy.
Experimental results
Research questions
- RQ1How can biometric data be securely integrated into RFID-based authentication without exposing raw biometric information?
- RQ2What lightweight cryptographic components can ensure strong security in resource-constrained RFID systems?
- RQ3Can the proposed protocol resist common attacks such as replay, impersonation, and key disclosure?
- RQ4How can mutual authentication and data secrecy be formally verified in a practical RFID-biometric system?
- RQ5What is the effectiveness of automated verification tools like AVISPA and SPAN in validating the protocol’s security?
Key findings
- The protocol successfully achieves mutual authentication between the RFID tag, reader, and server using minimal computational resources.
- The use of biometric hash functions ensures that raw biometric data is never stored or transmitted, preserving user privacy.
- Formal verification with AVISPA and SPAN confirmed the protocol’s resistance to common attacks and its ability to maintain secrecy.
- The integration of PRNG and cryptographic hash functions enhances security while remaining efficient for low-power devices.
- The protocol demonstrates strong security properties under the threat model, including protection against replay and impersonation attacks.
- The solution is formally proven secure in the symbolic model, validating its suitability for real-world deployment.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.