<?xml version="1.0" encoding="UTF-8"?>
<OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd">
  <responseDate>2026-07-25T01:58:13Z</responseDate>
  <request identifier="1957" metadataPrefix="oai_dc" verb="GetRecord">https://drops.dagstuhl.de/oai</request>
  <GetRecord>
    <record>
      <header>
        <identifier>oai:drops-oai.dagstuhl.de:1957</identifier>
        <datestamp>2024-03-06T11:08:30Z</datestamp>
        <setSpec>ddc:004</setSpec>
        <setSpec>open_access</setSpec>
      </header>
      <metadata>
        <oai_dc:dc xmlns:oai_dc="http://www.openarchives.org/OAI/2.0/oai_dc/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/oai_dc/ http://www.openarchives.org/OAI/2.0/oai_dc.xsd">
          <dc:title>Algebraic Attacks against Linear RFID Authentication Protocols</dc:title>
          <dc:creator>Krause, Matthias</dc:creator>
          <dc:creator>Stegemann, Dirk</dc:creator>
          <dc:subject>RFID Authentication</dc:subject>
          <dc:subject>HB+</dc:subject>
          <dc:subject>CKK</dc:subject>
          <dc:subject>CKK2</dc:subject>
          <dc:description>The limited computational resources available on RFID tags imply a&#13;
need for specially designed authentication protocols. The light weight&#13;
authentication protocol $extsf{HB}^+$ proposed by Juels and Weis seems currently&#13;
secure for several RFID applications, but is too slow for many practical&#13;
settings. &#13;
As a possible alternative, authentication protocols based on choosing&#13;
random elements from $L$ secret linear $n$-dimensional subspaces of&#13;
$GF(2)^{n+k}$ (so called linear $(n,k,L)$-protocols), have been considered. We show that to a certain extent, these protocols are vulnerable to algebraic&#13;
attacks.  Particularly, our approach allows to break Cicho'{n}, Klonowski and Kutyl owski's $	extsf{CKK}^2$-protocol,  a special linear&#13;
$(n,k,2)$-protocol,  for practically recommended parameters in less&#13;
than a second on a standard PC. Moreover, we show that&#13;
even  unrestricted $(n,k,L)$-protocols can be efficiently broken  if $L$ is too small.</dc:description>
          <dc:publisher>Schloss Dagstuhl – Leibniz-Zentrum für Informatik</dc:publisher>
          <dc:contributor>Matthias Krause and Dirk Stegemann</dc:contributor>
          <dc:date>2009</dc:date>
          <dc:relation>Is Part Of Dagstuhl Seminar Proceedings, Volume 9031, Symmetric Cryptography (2009)</dc:relation>
          <dc:type>InProceedings</dc:type>
          <dc:type>Text</dc:type>
          <dc:type>doc-type:ResearchArticle</dc:type>
          <dc:type>publishedVersion</dc:type>
          <dc:format>application/pdf</dc:format>
          <dc:identifier>doi:10.4230/DagSemProc.09031.3</dc:identifier>
          <dc:identifier>urn:nbn:de:0030-drops-19576</dc:identifier>
          <dc:identifier>https://drops.dagstuhl.de/entities/document/10.4230/DagSemProc.09031.3</dc:identifier>
          <dc:language>eng</dc:language>
          <dc:rights>https://creativecommons.org/licenses/by/4.0/legalcode</dc:rights>
        </oai_dc:dc>
      </metadata>
    </record>
  </GetRecord>
</OAI-PMH>
