Date Added: Jun 2009
The paper presents a formal model for stateful security protocols. This model is used to define ownership and ownership transfer as concepts as well as security properties. These definitions are based on an intuitive notion of ownership related to physical ownership. They are aimed at RFID systems, but should be applicable to any scenario sharing the same intuition of ownership. This paper discusses the connection between ownership and the notion of desynchronization resistance and gives the first formal definition of the latter. The paper applies the definitions to existing RFID protocols, exhibiting attacks on desynchronization resistance, secure ownership, and secure ownership transfer.