首页> 外文会议>Association for Computing Machinery Conference on Computer and Communications Security >RFIDs and Secret Handshakes: Defending Against Ghost-and-Leech Attacks and Unauthorized Reads with Context-Aware Communications
【24h】

RFIDs and Secret Handshakes: Defending Against Ghost-and-Leech Attacks and Unauthorized Reads with Context-Aware Communications

机译:RFIDS和秘密握手:使用上下文感知通信抵御Ghost-leech攻击和未经授权的读取

获取原文

摘要

We tackle the problem of defending against ghost-and-leech (a.k.a. proxying, relay, or man-in-the-middle) attacks against RFID tags and other contactless cards. The approach we take - which we dub secret handshakes - is to incorporate gesture recognition techniques directly on the RFID tags or contactless cards. These cards will only engage in wireless communications when they internally detect these secret handshakes. We demonstrate the effectiveness of this approach by implementing our secret handshake recognition system on a passive WISP RFID tag with a built-in accelerometer. Our secret handshakes approach is backward compatible with existing deployments of RFID tag and contactless card readers. Our approach was also designed to minimize the changes to the existing usage model of certain classes of RFID and contactless cards, like access cards kept in billfold and purse wallets, allowing the execution of secret handshakes without removing the card from one's wallet. Our techniques could extend to improving the security and privacy properties of other uses of RFID tags, like contactless payment cards.
机译:我们解决针对RFID标签和其他非接触式卡的扼杀幽灵和水蛭(A.K.A.代理,继电器或中间人)攻击的问题。我们采取的方法 - 我们配备秘密握手 - 是直接在RFID标签或非接触式卡上融入手势识别技术。当他们在内部检测到这些秘密握手时,这些卡片只会从事无线通信。我们通过在具有内置加速度计的被动Wisp RFID标签上实施我们的秘密握手识别系统来展示这种方法的有效性。我们的秘密握手方法是向后兼容RFID标签和非接触式读卡器的现有部署。我们的方法还旨在最大限度地减少某些类RFID和非接触式卡的现有使用模型的变化,例如在Billfold和Purse钱包中保存的访问卡,允许执行秘密握手,而不会从一个人的钱包中删除卡。我们的技术可以扩展到提高RFID标签的其他用途的安全性和隐私属性,如非接触式支付卡。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号