EPCGen2 Pseudorandom Number Generators: Analysis of J3Gen

Received: 18 December 2013; in revised form: 1 April 2014 / Accepted: 2 April 2014 / Published: 9 April 2014
Abstract: This paper analyzes the cryptographic security of J3Gen, a promising pseudo random number generator for low-cost passive Radio Frequency Identification (RFID) tags. Although J3Gen has been shown to fulfill the randomness criteria set by the EPCglobal Gen2 standard and is intended for security applications, we describe here two cryptanalytic attacks that question its security claims: (i) a probabilistic attack based on solving linear equation systems; and (ii) a deterministic attack based on the decimation of the output sequence. Numerical results, supported by simulations, show that for the specific recommended values of the configurable parameters, a low number of intercepted output bits are enough to break J3Gen. We then make some recommendations that address these issues.
Keywords: pseudo random number generators; security; cryptanalytic attack; Radio Frequency Identification; EPCglobal Gen2
