Can You Get into the Middle of Near Field Communication?

被引:8
作者
Akter, Sajeda [1 ]
Chakraborty, Tusher [1 ]
Khan, Taslim Arefin [1 ]
Chellappan, Sriram [2 ]
Al Islam, A. B. M. Alim [1 ]
机构
[1] Bangladesh Univ Engn & Technol, Dept CSE, Dhaka, Bangladesh
[2] Univ S Florida, Dept CSE, Tampa, FL 33620 USA
来源
2017 IEEE 42ND CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN) | 2017年
基金
美国国家科学基金会;
关键词
NFC; Contactless payment; Attacks; Security;
D O I
10.1109/LCN.2017.39
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
A recent development emanating from the widely used RFID technology is Near Field Communication (NFC). Basically, NFC is a popular short range (<10cm) wireless communication technology with applications in areas sensitive to security and privacy concerns including contact-less payment. Since NFC communications require very close proximity between two communicating devices (for example a smartcard and a reader), it is generally believed that Man-in-the-Middle (MITM) attacks are practically infeasible here. On the contrary to this general belief, in this paper, we successfully establish MITM attacks in NFC communications between a passive tag and an active reader. We present physical fundamentals of the attack, our engineering design, and results of our successful implementation. We also present practical impacts of the attack from the perspective of how a malicious user can leverage our MITM attack to compromise integrity of contact-less payment transactions. Finally, we present insights to combat the MITM attack in NFC communications towards the end of the paper.
引用
收藏
页码:365 / 373
页数:9
相关论文
共 23 条
[1]  
[Anonymous], THESIS
[2]  
[Anonymous], 2009, VISA INTEGRATED CIRC
[3]  
[Anonymous], 2013, The design of Rijndael: AES-the advanced encryption standard
[4]  
[Anonymous], 2005, PAYPASS M CHIP VERSI
[5]  
[Anonymous], 2016, CONTACTLESS SPECIFIC
[6]  
Bakhoff M., 2014, EMV CHIP AND PIN PRO
[7]  
Cortese P., 2010, 2010 IEEE INT C RFID
[8]  
Coskun V., 2014, INT J COMPUTER ELECT
[9]  
De Ruiter Joeri, 2011, JOINT WORKSH THEOR S
[10]  
Di Ma Anudath, 2013, IEEE T DEPENDABLE SE, V10