RFID (Radio-Frequency Identification) applications have been widely developed and the relative researches have increased noticeably. These applications use the technology of RFID to identify objects which attached tag to create a new convenient application area for people such as medical drugs managements, aging people caring, supply chain etc. But they also suffer from the security issues because the insecure communication channel between readers and tags. While, in traditional RFID systems, it is believed that the channel between reads and backend server is secure. Therefore, the mutual authentication between reader and tag is one or the most important issue in RFID system. In 2012, Chou et al. proposed a mutual authentication protocol using ECC (Elliptic Curve Cryptography) and claimed their scheme could resist various kinds of attacks. However, we have found that their protocol cannot resist the replay attack. In this paper, we will present how to execute the replay attack on Chou et al.' protocol. Then we propose an improvement protocol. And the improvement protocol will be proved that it has the replay attack resistance.