On Bad Randomness and Cloning of Contactless Payment and Building Smart Cards

被引:3
作者
Courtois, Nicolas T. [1 ]
Hulme, Daniel [1 ]
Hussain, Kumail [1 ]
Gawinecki, Jerzy A.
Grajek, Marek
机构
[1] UCL, London WC1E 6BT, England
来源
IEEE CS SECURITY AND PRIVACY WORKSHOPS (SPW 2013) | 2013年
关键词
Random Number Generators (RNG); human factors; cryptography; smart cards; RFID; building access control; contactless payments; HID Prox; HID iClass; MiFare Classic;
D O I
10.1109/SPW.2013.29
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In this paper we study the randomness of some random numbers found in real-life smart card products. We have studied a number of symmetric keys, codes and random nonces in the most prominent contactless smart cards used in buildings, small payments and public transportation used by hundreds of millions of people every day. Furthermore we investigate a number of technical questions in order to see to what extent the vulnerabilities we have discovered could be exploited by criminals. In particular we look at the case MiFare Classic cards, of which some two hundred million are still in use worldwide. We have examined some 50 real-life cards from different countries to discover that it is not entirely clear if what was previously written about this topic is entirely correct. These facts are highly relevant to the practical feasibility of card cloning in order to enter some buildings, make small purchases or in public transportation in many countries. We also show examples of serious security issues due to poor entropy with another very popular contactless smart card used in many buildings worldwide.
引用
收藏
页码:105 / 110
页数:6
相关论文
共 18 条
  • [1] Adebanke A., 2012, THESIS U COLL LONDON
  • [2] [Anonymous], USENIX SEC S
  • [3] Instant ciphertext-only cryptanalysis of GSM encrypted communication
    Barkan, Elad
    Biham, Eli
    Keller, Nathan
    [J]. JOURNAL OF CRYPTOLOGY, 2008, 21 (03) : 392 - 429
  • [4] Costin A., MFCUK OPEN SOURCE C
  • [5] COURTOIS N, ALGEBRAIC ATTACKS MI
  • [6] Courtois N., 2007, CARTE PUCE 293 SLIDE
  • [7] Courtois N., 2009, 2009 WORKSH RFID SEC
  • [8] Courtois N., 2012, CHIP CLOUD SEC FOR S
  • [9] Courtois NT, 2009, SECRYPT 2009: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, P331
  • [10] Courtois NT, 2003, LECT NOTES COMPUT SC, V2656, P345