{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,28]],"date-time":"2026-02-28T04:27:56Z","timestamp":1772252876401,"version":"3.50.1"},"reference-count":47,"publisher":"MDPI AG","issue":"21","license":[{"start":{"date-parts":[[2019,11,1]],"date-time":"2019-11-01T00:00:00Z","timestamp":1572566400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Despite the many conveniences of Radio Frequency Identification (RFID) systems, the underlying open architecture for communication between the RFID devices may lead to various security threats. Recently, many solutions were proposed to secure RFID systems and many such systems are based on only lightweight primitives, including symmetric encryption, hash functions, and exclusive OR operation. Many solutions based on only lightweight primitives were proved insecure, whereas, due to resource-constrained nature of RFID devices, the public key-based cryptographic solutions are unenviable for RFID systems. Very recently, Gope and Hwang proposed an authentication protocol for RFID systems based on only lightweight primitives and claimed their protocol can withstand all known attacks. However, as per the analysis in this article, their protocol is infeasible and is vulnerable to collision, denial-of-service (DoS), and stolen verifier attacks. This article then presents an improved realistic and lightweight authentication protocol to ensure protection against known attacks. The security of the proposed protocol is formally analyzed using Burrows Abadi-Needham (BAN) logic and under the attack model of automated security verification tool ProVerif. Moreover, the security features are also well analyzed, although informally. The proposed protocol outperforms the competing protocols in terms of security.<\/jats:p>","DOI":"10.3390\/s19214752","type":"journal-article","created":{"date-parts":[[2019,11,1]],"date-time":"2019-11-01T12:30:50Z","timestamp":1572611450000},"page":"4752","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":67,"title":["Securing IoT-Based RFID Systems: A Robust Authentication Protocol Using Symmetric Cryptography"],"prefix":"10.3390","volume":"19","author":[{"given":"Khwaja","family":"Mansoor","sequence":"first","affiliation":[{"name":"Department of Computer Science, Air University Islamabad, Islamabad 44000, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7474-0405","authenticated-orcid":false,"given":"Anwar","family":"Ghani","sequence":"additional","affiliation":[{"name":"Department of Computer Science &amp; Software Engineering, International Islamic University Islamabad, Islamabad 44000, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9321-6956","authenticated-orcid":false,"given":"Shehzad","family":"Chaudhry","sequence":"additional","affiliation":[{"name":"Department of Computer Engineering, Faculty of Engineering and Architecture, Istanbul Gelisim University, Istanbul 34310, Turkey"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6605-498X","authenticated-orcid":false,"given":"Shahaboddin","family":"Shamshirband","sequence":"additional","affiliation":[{"name":"Department for Management of Science and Technology Development, Ton Duc Thang University, Ho Chi Minh City, Viet Nam"},{"name":"Faculty of Information Technology, Ton Duc Thang University, Ho Chi Minh City, Viet Nam"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shahbaz","family":"Ghayyur","sequence":"additional","affiliation":[{"name":"Department of Computer Science &amp; Software Engineering, International Islamic University Islamabad, Islamabad 44000, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4842-0613","authenticated-orcid":false,"given":"Amir","family":"Mosavi","sequence":"additional","affiliation":[{"name":"Faculty of Health, Queensland University of Technology, Victoria Park Road, Kelvin Grove, QLD 4059, Australia"},{"name":"Kando Kalman Faculty of Electrical Engineering, Obuda University, 1034 Budapest, Hungary"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2019,11,1]]},"reference":[{"key":"ref_1","unstructured":"Rouse, M. (2019, September 03). Internet of Things (IoT). Available online: https:\/\/internetofthingsagenda.techtarget.com\/definition\/Internet-of-Things-IoT."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1368","DOI":"10.1109\/JSEN.2015.2502401","article-title":"BSN-Care: A secure IoT-based modern healthcare system using body sensor network","volume":"16","author":"Gope","year":"2016","journal-title":"IEEE Sens. J."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"271","DOI":"10.1016\/j.cose.2015.05.004","article-title":"A realistic lightweight authentication protocol preserving strong anonymity for securing RFID system","volume":"55","author":"Gope","year":"2015","journal-title":"Comput. Secur."},{"key":"ref_4","unstructured":"Peris-Lopez, P., Hernandez-Castro, J.C., Estevez-Tapiador, J.M., and Ribagorda, A. (2016). Lightweight cryptography for low-cost RFID tags. Security in RFID and Sensor Networks, CRC Press."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"629","DOI":"10.1016\/j.future.2017.06.023","article-title":"Lightweight and privacy-preserving RFID authentication scheme for distributed IoT infrastructure with secure localization services for smart city environment","volume":"83","author":"Gope","year":"2018","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Kitsos, P. (2016). Security in RFID and Sensor Networks, CRC Press.","DOI":"10.1201\/9781420068405"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"2581","DOI":"10.1002\/sec.1488","article-title":"Efficient identity authentication and encryption technique for high throughput RFID system","volume":"9","author":"Hsu","year":"2016","journal-title":"Secur. Commun. Netw."},{"key":"ref_8","unstructured":"Simon, P.M.G., Riggert, E.F., and Trivelpiece, S.E. (2016). System and Method for Reading RFID Tags Across a Portal. (9,519,811), U.S. Patent."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"919","DOI":"10.1007\/s12652-017-0485-5","article-title":"A lightweight and anonymous RFID tag authentication protocol with cloud assistance for e-healthcare applications","volume":"9","author":"Wu","year":"2018","journal-title":"J. Ambient Intell. Humanized Comput."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"7273","DOI":"10.1109\/ACCESS.2018.2890389","article-title":"Ultralightweight Mutual Authentication RFID Protocol for Blockchain Enabled Supply Chains","volume":"7","author":"Sidorov","year":"2019","journal-title":"IEEE Access"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Noman, A.T., Hossain, S., Islam, S., Islam, M.E., Ahmed, N., and Chowdhury, M.M. (2018, January 13\u201315). Design and Implementation of Microcontroller Based Anti-Theft Vehicle Security System using GPS, GSM and RFID. Proceedings of the 2018 4th International Conference on Electrical Engineering and Information & Communication Technology (iCEEiCT), Dhaka, Bangladesh.","DOI":"10.1109\/CEEICT.2018.8628051"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"133","DOI":"10.1016\/j.adhoc.2013.02.004","article-title":"A secure ECC-based RFID authentication scheme integrated with ID-verifier transfer protocol","volume":"18","author":"Liao","year":"2014","journal-title":"Ad Hoc Netw."},{"key":"ref_13","first-page":"37","article-title":"RFID mutual authentication protocol based on synchronized secret","volume":"7","author":"Kim","year":"2013","journal-title":"Int. J. Secur. Its Appl."},{"key":"ref_14","unstructured":"Cha, J.R., and Kim, J.H. (2005, January 20\u201322). Novel anti-collision algorithms for fast object identification (RFID) system. Proceedings of the 11th International Conference on Parallel and Distributed Systems, Washington, DC, USA."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"El Beqqal, M., and Azizi, M. (2017, January 19\u201320). Classification of major security attacks against RFID systems. Proceedings of the International Conference on Wireless Technologies, Embedded and Intelligent Systems (WITS), Fez, Morocco.","DOI":"10.1109\/WITS.2017.7934622"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"1085","DOI":"10.1007\/s11227-016-1849-x","article-title":"Cryptanalysis of a novel ultra-lightweight mutual authentication protocol for IoT devices using RFID tags","volume":"73","author":"Tewari","year":"2017","journal-title":"J. Supercomput."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Ayaz, U., Haq, T.A., Taimour, S., Mansoor, K., and Mahmood, S. (2018, January 21\u201322). An Enhanced Biometric Based RFID Authentication Scheme Defending Against Illegitimate Access. Proceedings of the 14th International Conference on Emerging Technologies (ICET), Islamabad, Pakistan.","DOI":"10.1109\/ICET.2018.8603650"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"46","DOI":"10.1007\/s10916-014-0046-9","article-title":"A secure RFID authentication protocol for healthcare environments using elliptic curve cryptosystem","volume":"38","author":"Zhao","year":"2014","journal-title":"J. Med. Syst."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"165","DOI":"10.1007\/s10916-016-0521-6","article-title":"A provably secure RFID authentication protocol based on elliptic curve for healthcare environments","volume":"40","author":"Farash","year":"2016","journal-title":"J. Med. Syst."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Burmester, M., De Medeiros, B., and Motta, R. (2008, January 18\u201319). Robust, anonymous RFID authentication with constant key-lookup. Proceedings of the 2008 ACM symposium on Information, computer and communications security, Tokyo, Japan.","DOI":"10.1145\/1368310.1368351"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Cai, S., Li, Y., Li, T., and Deng, R.H. (2009, January 16\u201319). Attacks and improvements to an RIFD mutual authentication protocol and its extensions. Proceedings of the second ACM conference on Wireless network security, Zurich, Switzerland.","DOI":"10.1145\/1514274.1514282"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Gaubatz, G., Kaps, J.P., Ozturk, E., and Sunar, B. (2005, January 8\u201312). State of the art in ultra-low power public key cryptography for wireless sensor networks. Proceedings of the Third IEEE International Conference on Pervasive Computing and Communications Workshops, PerCom Workshops, Kauai Island, HI, USA.","DOI":"10.1109\/PERCOMW.2005.76"},{"key":"ref_23","unstructured":"Yang, J., Park, J., Lee, H., Ren, K., and Kim, K. (2005, January 14\u201315). Mutual authentication protocol. Proceedings of the Workshop on RFID and lightweight crypto, Graz, Austria."},{"key":"ref_24","unstructured":"Kang, S.Y., and Lee, I.Y. (2007, January 10\u201312). A Study on low-cost RFID system management with mutual authentication scheme in ubiquitous. Proceedings of the Asia-Pacific Network Operations and Management Symposium, Sapporo, Japan."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"587","DOI":"10.1016\/j.ijpe.2007.05.008","article-title":"Radio frequency identification (RFID) implementation in the service sector: A customer-facing diffusion model","volume":"112","author":"Lee","year":"2008","journal-title":"Int. J. Prod. Econ."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Qingling, C., Yiju, Z., and Yonghua, W. (2008, January 3\u20134). A minimalist mutual authentication protocol for RFID system & BAN logic analysis. Proceedings of the International Colloquium on Computing, Communication, Control, and Management, CCCM, Guangzhou, China.","DOI":"10.1109\/CCCM.2008.305"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"521","DOI":"10.1007\/s10796-009-9216-6","article-title":"A lightweight anti-desynchronization RFID authentication protocol","volume":"12","author":"Zhou","year":"2010","journal-title":"Inf. Syst. Front."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"387","DOI":"10.1016\/j.dss.2010.09.005","article-title":"RFID mutual authentication protocols","volume":"50","author":"Piramuthu","year":"2011","journal-title":"Decis. Support Syst."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"571","DOI":"10.1016\/j.cam.2013.09.073","article-title":"Cryptanalysis of the Cho et al. protocol: A hash-based RFID tag mutual authentication protocol","volume":"259","author":"Safkhani","year":"2014","journal-title":"J. Comput. Appl. Math."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"1400","DOI":"10.1109\/TWC.2008.061012","article-title":"Secure and serverless RFID authentication and search protocols","volume":"7","author":"Tan","year":"2008","journal-title":"IEEE Trans. Wirel. Commun."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1016\/j.camwa.2012.02.025","article-title":"Consideration on the brute-force attack cost and retrieval cost: A hash-based radio-frequency identification (RFID) tag mutual authentication protocol","volume":"69","author":"Cho","year":"2015","journal-title":"Comput. Math. Appl."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Naeem, M., Chaudhry, S.A., Mahmood, K., Karuppiah, M., and Kumari, S. (2019). A scalable and secure RFID mutual authentication protocol using ECC for Internet of Things. Int. J. Commun. Syst.","DOI":"10.1002\/dac.3906"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"47","DOI":"10.1007\/s10916-014-0047-8","article-title":"An efficient RFID authentication protocol to enhance patient medication safety using elliptic curve cryptography","volume":"38","author":"Zhang","year":"2014","journal-title":"J. Med. Syst."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"3504","DOI":"10.1007\/s11227-015-1601-y","article-title":"An improved and robust biometrics-based three factor authentication scheme for multiserver environments","volume":"74","author":"Chaudhry","year":"2018","journal-title":"J. Supercomput."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"2437","DOI":"10.1109\/JSYST.2017.2765178","article-title":"Identification of Threats and Security Risk Assessments for Recursive Internet Architecture","volume":"12","author":"Asgari","year":"2018","journal-title":"IEEE Syst. J."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"7996","DOI":"10.1109\/TIE.2018.2807383","article-title":"An Anonymous ECC-Based Self-Certified Key Distribution Scheme for the Smart Grid","volume":"65","author":"Nikooghadam","year":"2018","journal-title":"IEEE Trans. Ind. Electron."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"9570","DOI":"10.1109\/TVT.2016.2621354","article-title":"A Secure and Authenticated Key Management Protocol (SA-KMP) for Vehicular Networks","volume":"65","author":"Tan","year":"2016","journal-title":"IEEE Trans. Veh. Technol."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"1595","DOI":"10.1007\/s10586-017-1088-9","article-title":"An improved anonymous authentication scheme for distributed mobile cloud computing services","volume":"22","author":"Chaudhry","year":"2019","journal-title":"Cluster Comput."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"2884","DOI":"10.1109\/JIOT.2017.2714179","article-title":"Chaotic Map-Based Anonymous User Authentication Scheme With User Biometrics and Fuzzy Extractor for Crowdsourcing Internet of Things","volume":"5","author":"Roy","year":"2018","journal-title":"IEEE Internet Things J."},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"3376","DOI":"10.1109\/ACCESS.2017.2673239","article-title":"Lightweight three-factor authentication and key agreement protocol for internet-integrated wireless sensor networks","volume":"5","author":"Jiang","year":"2017","journal-title":"IEEE Access"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"e3814","DOI":"10.1002\/dac.3814","article-title":"An ameliorated two-factor anonymous key exchange authentication protocol for mobile client-server environment","volume":"31","author":"Mahmood","year":"2018","journal-title":"Int. J. Commun. Syst."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"e5295","DOI":"10.1002\/cpe.5295","article-title":"A lightweight anonymous mutual authentication and key agreement scheme for WBAN","volume":"31","author":"Xu","year":"2019","journal-title":"Concurr. Comput. Pract. Exp."},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"131","DOI":"10.1016\/j.neucom.2019.03.020","article-title":"Security enhancement of an anonymous roaming authentication scheme with two-factor security in smart city","volume":"347","author":"Xie","year":"2019","journal-title":"Neurocomputing"},{"key":"ref_44","unstructured":"Kyntaja, T. A Logic of Authentication by Burrows, Abadi and Needham, Science Helsinki University of Technology. Available online: http:\/\/www.tml.tkk.fi\/Opinnot\/Tik-110.501\/1995\/ban.html."},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1561\/3300000004","article-title":"Modeling and verifying security protocols with the applied pi calculus and ProVerif","volume":"1","author":"Blanchet","year":"2016","journal-title":"Found. Trends Privacy Secur."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"1057","DOI":"10.1016\/j.patcog.2006.05.030","article-title":"An improved biohashing for human authentication","volume":"40","author":"Lumini","year":"2007","journal-title":"Pattern Recognit."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"1005","DOI":"10.1109\/SURV.2013.091513.00050","article-title":"A survey of SIP authentication and key agreement schemes","volume":"16","author":"Kilinc","year":"2014","journal-title":"IEEE Commun. Surv. Tutor."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/19\/21\/4752\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T13:31:13Z","timestamp":1760189473000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/19\/21\/4752"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,11,1]]},"references-count":47,"journal-issue":{"issue":"21","published-online":{"date-parts":[[2019,11]]}},"alternative-id":["s19214752"],"URL":"https:\/\/doi.org\/10.3390\/s19214752","relation":{"has-preprint":[{"id-type":"doi","id":"10.20944\/preprints201907.0298.v1","asserted-by":"object"}]},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,11,1]]}}}