Featured Research

from universities, journals, and other organizations

The perfect clone: Researchers hack RFID smartcards

Date:
December 8, 2011
Source:
Ruhr-Universitaet-Bochum
Summary:
Professional safecrackers use a stethoscope to find the correct combination by listening to the clicks of the lock. Researchers have now demonstrated how to bypass the security mechanisms of a widely used contactless smartcard in a similar way. Employing so-called “Side-Channel Analysis” the researchers can break the cryptography of millions of cards that are used all around the world.

Measuring the electro-magnetic field.
Credit: Image courtesy of Ruhr-Universitaet-Bochum

Professional safecrackers use a stethoscope to find the correct combination by listening to the clicks of the lock. Researchers at the Ruhr-University Bochum have now demonstrated how to bypass the security mechanisms of a widely used contactless smartcard in a similar way. Employing so-called "Side-Channel Analysis" the researchers of the Chair for Embedded Security (Prof. Dr.-Ing. Christof Paar) can break the cryptography of millions of cards that are used all around the world.

Related Articles


Mathematically secure

RFID smartcards (Radio Frequency Identification) of the type DESFire MF3ICD40 are widely employed in payment and access control systems. The security of these cards is based on Triple-DES, a cipher that is unbreakable from a purely mathematic point of view. DESFire cards are for instance used by the public transport agencies in Melbourne, San Francisco and Prague. The DESFire MF3ICD40 is manufactured by NXP, the former semiconductor division of Philips Electronics.

Fluctuations of the magnetic field

A person is identified as a passenger, employee or customer when his RFID smartcard is placed in the proximity of a reader. To guarantee the necessary level of security, a secret key is stored on the integrated chip inside the card. But just like for the safe, the security mechanism produces the electronic equivalent of the clicks of a mechanic lock. "We measured the power consumption of the chip during the encryption and decryption with a small probe," says David Oswald. The fluctuations of the electro-magnetic field allow the researchers to conclude to the full 112-bit secret key of the smartcard.

Low cost, big damage

Having extracted the keys, an attacker can create an unlimited number of undetectable clones of a given card. The required time and effort are quite low: "For our measurements, we needed a DESFire MF3ICD40 card, an RFID reader, the probe and an oscilloscope to measure the power consumption," says Oswald. This equipment only costs a few thousand euros. Having obtained knowledge on the characteristic properties of the smartcard, the attack takes three to seven hours. The manufacturer NXP confirmed the security hole in the meanwhile and recommends his customers to upgrade to a newer version of the card.

Insufficient countermeasures

Already back in 2008, researchers around Prof. Dr.-Ing. Christof Paar used Side-Channel Analysis to break supposedly secure systems. Three years ago, garage and car doors "mysteriously" opened for the researchers of the Chair for Embedded Security. The employed KeeLoq RFID system -- which customers and manufacturers trusted blindly before -- turned out to be highly susceptible to Side-Channel Analysis, researchers said.


Story Source:

The above story is based on materials provided by Ruhr-Universitaet-Bochum. Note: Materials may be edited for content and length.


Cite This Page:

Ruhr-Universitaet-Bochum. "The perfect clone: Researchers hack RFID smartcards." ScienceDaily. ScienceDaily, 8 December 2011. <www.sciencedaily.com/releases/2011/11/111103081340.htm>.
Ruhr-Universitaet-Bochum. (2011, December 8). The perfect clone: Researchers hack RFID smartcards. ScienceDaily. Retrieved March 4, 2015 from www.sciencedaily.com/releases/2011/11/111103081340.htm
Ruhr-Universitaet-Bochum. "The perfect clone: Researchers hack RFID smartcards." ScienceDaily. www.sciencedaily.com/releases/2011/11/111103081340.htm (accessed March 4, 2015).

Share This


More From ScienceDaily



More Computers & Math News

Wednesday, March 4, 2015

Featured Research

from universities, journals, and other organizations


Featured Videos

from AP, Reuters, AFP, and other news services

Forensic Holodeck Creates 3D Crime Scenes

Forensic Holodeck Creates 3D Crime Scenes

Reuters - Innovations Video Online (Mar. 3, 2015) A holodeck is no longer the preserve of TV sci-fi classic Star Trek, thanks to researchers from the Institute of Forensic Medicine Zurich, who have created what they say is the first system in the world to visualise the 3D data of forensic scans. Jim Drury saw it in operation. Video provided by Reuters
Powered by NewsLook.com
HP to Buy Aruba Networks in $3B Deal

HP to Buy Aruba Networks in $3B Deal

Reuters - Business Video Online (Mar. 2, 2015) Hewlett-Packard is boosting its mobile computing business... buying California-based Aruba Networks- a wi-fi network gear maker for $24.67 per share. Leah Duncan reports. Video provided by Reuters
Powered by NewsLook.com
Everything You Need To Know About Mobile Payments In 2015

Everything You Need To Know About Mobile Payments In 2015

Newsy (Mar. 2, 2015) This year, mobile payments might finally catch on. Here are the things you need to know to stay on top of the latest developments. Video provided by Newsy
Powered by NewsLook.com
Can Curved Screen Give Samsung the Edge?

Can Curved Screen Give Samsung the Edge?

Reuters - Business Video Online (Mar. 2, 2015) South Korea&apos;s Samsung Electronics Co Ltd unveiled its latest Galaxy S smartphones, featuring a slim body made from aircraft-grade metal, in a bid to reclaim the throne of undisputed global smartphone leader from Apple Inc. Hayley Platt reports. Video provided by Reuters
Powered by NewsLook.com

Search ScienceDaily

Number of stories in archives: 140,361

Find with keyword(s):
Enter a keyword or phrase to search ScienceDaily for related topics and research stories.

Save/Print:
Share:

Breaking News:

Strange & Offbeat Stories


Space & Time

Matter & Energy

Computers & Math

In Other News

... from NewsDaily.com

Science News

Health News

Environment News

Technology News



Save/Print:
Share:

Free Subscriptions


Get the latest science news with ScienceDaily's free email newsletters, updated daily and weekly. Or view hourly updated newsfeeds in your RSS reader:

Get Social & Mobile


Keep up to date with the latest news from ScienceDaily via social networks and mobile apps:

Have Feedback?


Tell us what you think of ScienceDaily -- we welcome both positive and negative comments. Have any problems using the site? Questions?
Mobile: iPhone Android Web
Follow: Facebook Twitter Google+
Subscribe: RSS Feeds Email Newsletters
Latest Headlines Health & Medicine Mind & Brain Space & Time Matter & Energy Computers & Math Plants & Animals Earth & Climate Fossils & Ruins