%0 Conference Proceedings %T Modeling Privacy for Off-Line RFID Systems %+ Institute for Computing and Information Sciences [Nijmegen] (ICIS) %A Garcia, Flavio D. %A Rossum, Peter %< avec comité de lecture %( Lecture Notes in Computer Science %B 9th IFIP WG 8.8/11.2 International Conference on Smart Card Research and Advanced Applications (CARDIS) %C Passau, Germany %Y Dieter Gollmann; Jean-Louis Lanet; Julien Iguchi-Cartigny %I Springer %3 Smart Card Research and Advanced Application %V LNCS-6035 %P 194-208 %8 2010-04-14 %D 2010 %R 10.1007/978-3-642-12510-2_14 %Z Computer Science [cs]/Digital Libraries [cs.DL]Conference papers %X This paper establishes a novel model for RFID schemes where readers are not continuously connected to the back office, but only periodically. Furthermore, adversaries are not only capable of compromising tags, but also of compromising readers. This more properly models large scale deployment of RFID technology such as in public transport ticketing systems and supply-chain management systems. In this model we define notions of security (only legitimate tags can authenticate) and of privacy (no adversary is capable of tracking legitimate tags). We show that privacy is always lost at the moment that a reader is compromised and we develop notions of forward and backward privacy with respect to reader corruption. This models the property that tags cannot be traced, under mild additional assumptions, for the time slots before and after reader corruption. We exhibit two protocols that only use hashing that achieve these security and privacy notions and give proofs in the random oracle model. %G English %2 https://inria.hal.science/hal-01056106/document %2 https://inria.hal.science/hal-01056106/file/RFIDPriv.pdf %L hal-01056106 %U https://inria.hal.science/hal-01056106 %~ IFIP-LNCS %~ IFIP %~ IFIP-LNCS-6035 %~ IFIP-TC %~ IFIP-TC11 %~ IFIP-TC8 %~ IFIP-WG11-2 %~ IFIP-2010 %~ IFIP-CARDIS %~ IFIP-WG8-8