Picking virtual pockets using relay attacks on contactless smartcard systems

被引:84
作者
Kfir, Z [1 ]
Wool, A [1 ]
机构
[1] Tel Aviv Univ, Sch Elect Engn, IL-69978 Tel Aviv, Israel
来源
First International Conference on Security and Privacy for Emerging Areas in Communications Networks, Proceedings | 2005年
关键词
RFID; contactless smartcard; payment systems; security;
D O I
10.1109/SECURECOMM.2005.32
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A contactless smartcard is a smartcard that can communicate with other devices without any physical connection, using Radio-Frequency Identifier (RFID) technology. Contactless smartcards are becoming increasingly popular with applications like credit-cards, national-ID, passports, physical access. The security of such applications is clearly critical. A key feature of RFID-based systems is their very short range: typical systems are designed to operate at a range of approximate to 10cm. In this study we show that contactless smartcard technology is vulnerable to relay attacks: An attacker can trick the reader into communicating with a victim smartcard that is very far away. A "low-tech" attacker can build a pick-pocket system that can remotely use a victim contactless smartcard, without the victim's knowledge. The attack system consists of two devices, which we call the "ghost" and the "leech". We discuss basic designs for the attacker's equipment, and explore their possible operating ranges. We show that the ghost can be up to 50m away from the card reader - 3 orders of magnitude higher than the nominal range. We also show that the leech can be up to 50cm away from the the victim card. The main characteristics of the attack are: orthogonality to any security protocol, unlimited distance between the attacker and the victim, and low cost of the attack system.
引用
收藏
页码:47 / 58
页数:12
相关论文
共 43 条
[1]  
ALLIANCE SC, 2003, PRIVACY SECURE IDENT
[2]  
ALLIANCE SC, 2004, NIST REPORT
[3]  
ALLIANCE SC, 2003, IND NEWS
[4]  
[Anonymous], 15408 ISOIEC
[5]  
BONO S, SECURITY ANAL CRYPTO
[6]  
*CEPT, 2004, 7003 CEPT
[7]  
European Radiocommunications Committee (ERC), 1999, 69 ERC
[8]  
*EUROSMART, VOIC SMART CARD IND
[9]  
*FCC, 2001, FCC 15
[10]  
Finkenzeller K., 2003, RFID HDB