Forum for Science, Industry and Business

Sponsored by:     3M 
Search our Site:

 

The perfect clone: RUB researchers hack RFID smartcards

03.11.2011
Extracting key from electro-magnetic emanations

Professional safecrackers use a stethoscope to find the correct combination by listening to the clicks of the lock. Researchers at the Ruhr-University Bochum have now demonstrated how to bypass the security mechanisms of a widely used contactless smartcard in a similar way. Employing so-called “Side-Channel Analysis” the researchers of the Chair for Embedded Security (Prof. Dr.-Ing. Christof Paar) can break the cryptography of millions of cards that are used all around the world.


Measuring the electro-magnetic field

Mathematically secure

RFID smartcards (Radio Frequency Identification) of the type DESFire MF3ICD40 are widely employed in payment and access control systems. The security of these cards is based on Triple-DES, a cipher that is unbreakable from a purely mathematic point of view. DESFire cards are for instance used by the public transport agencies in Melbourne, San Francisco and Prague. The DESFire MF3ICD40 is manufactured by NXP, the former semiconductor division of Philips Electronics.

Fluctuations of the magnetic field

A person is identified as a passenger, employee or customer when his RFID smartcard is placed in the proximity of a reader. To guarantee the necessary level of security, a secret key is stored on the integrated chip inside the card. But just like for the safe, the security mechanism produces the electronic equivalent of the clicks of a mechanic lock. “We measured the power consumption of the chip during the encryption and decryption with a small probe”, says David Oswald. The fluctuations of the electro-magnetic field allow the researchers to conclude to the full 112-bit secret key of the smartcard.

Low cost, big damage

Having extracted the keys, an attacker can create an unlimited number of undetectable clones of a given card. The required time and effort are quite low: “For our measurements, we needed a DESFire MF3ICD40 card, an RFID reader, the probe and an oscilloscope to measure the power consumption”, says Oswald. This equipment only costs a few thousand euros. Having obtained knowledge on the characteristic properties of the smartcard, the attack takes three to seven hours. The manufacturer NXP confirmed the security hole in the meanwhile and recommends his customers to upgrade to a newer version of the card.

Insufficient countermeasures

Already back in 2008, researchers around Prof. Dr.-Ing. Christof Paar used Side-Channel Analysis to break supposedly secure systems. Three years ago, garage and car doors “mysteriously” opened for the researchers of the Chair for Embedded Security. The employed KeeLoq RFID system – which customers and manufacturers trusted blindly before – turned out to be highly susceptible to Side-Channel Analysis.

Further information

Prof. Dr.-Ing. Christof Paar, Chair for Embedded Security, Building ID 2/607, Tel. +49 234 32 22994, christof.paar@rub.de

Homepage: http://www.emsec.rub.de

Dr. Josef König | idw
Further information:
http://www.emsec.rub.de

More articles from Information Technology:

nachricht Research alliance: TRUMPF and Fraunhofer IPA ramping up artificial intelligence for industrial use
06.08.2020 | Fraunhofer-Institut für Produktionstechnik und Automatisierung IPA

nachricht Novel approach improves graphene-based supercapacitors
03.08.2020 | University of Technology Sydney

All articles from Information Technology >>>

The most recent press releases about innovation >>>

Die letzten 5 Focus-News des innovations-reports im Überblick:

Im Focus: ScanCut project completed: laser cutting enables more intricate plug connector designs

Scientists at the Fraunhofer Institute for Laser Technology ILT have come up with a striking new addition to contact stamping technologies in the ERDF research project ScanCut. In collaboration with industry partners from North Rhine-Westphalia, the Aachen-based team of researchers developed a hybrid manufacturing process for the laser cutting of thin-walled metal strips. This new process makes it possible to fabricate even the tiniest details of contact parts in an eco-friendly, high-precision and efficient manner.

Plug connectors are tiny and, at first glance, unremarkable – yet modern vehicles would be unable to function without them. Several thousand plug connectors...

Im Focus: New Strategy Against Osteoporosis

An international research team has found a new approach that may be able to reduce bone loss in osteoporosis and maintain bone health.

Osteoporosis is the most common age-related bone disease which affects hundreds of millions of individuals worldwide. It is estimated that one in three women...

Im Focus: AI & single-cell genomics

New software predicts cell fate

Traditional single-cell sequencing methods help to reveal insights about cellular differences and functions - but they do this with static snapshots only...

Im Focus: TU Graz Researchers synthesize nanoparticles tailored for special applications

“Core-shell” clusters pave the way for new efficient nanomaterials that make catalysts, magnetic and laser sensors or measuring devices for detecting electromagnetic radiation more efficient.

Whether in innovative high-tech materials, more powerful computer chips, pharmaceuticals or in the field of renewable energies, nanoparticles – smallest...

Im Focus: Tailored light inspired by nature

An international research team with Prof. Cornelia Denz from the Institute of Applied Physics at the University of Münster develop for the first time light fields using caustics that do not change during propagation. With the new method, the physicists cleverly exploit light structures that can be seen in rainbows or when light is transmitted through drinking glasses.

Modern applications as high resolution microsopy or micro- or nanoscale material processing require customized laser beams that do not change during...

All Focus news of the innovation-report >>>

Anzeige

Anzeige

VideoLinks
Industry & Economy
Event News

“Conference on Laser Polishing – LaP 2020”: The final touches for surfaces

23.07.2020 | Event News

Conference radar for cybersecurity

21.07.2020 | Event News

Contact Tracing Apps against COVID-19: German National Academy Leopoldina hosts international virtual panel discussion

07.07.2020 | Event News

 
Latest News

Anode material for safe batteries with a long cycle life

06.08.2020 | Power and Electrical Engineering

Turning carbon dioxide into liquid fuel

06.08.2020 | Life Sciences

Tellurium makes the difference

06.08.2020 | Life Sciences

VideoLinks
Science & Research
Overview of more VideoLinks >>>