首页> 外文会议>Workshop on RFID and IoT Security >Practical Relay Attack on Contactless Transactions by Using NFC Mobile Phones
【24h】

Practical Relay Attack on Contactless Transactions by Using NFC Mobile Phones

机译:使用NFC手机对非接触式交易的实用继电器攻击

获取原文

摘要

Contactless technology is widely used in security sensitive applications, including identification, payment and access-control systems. Near Field Communication (NFC) is a short-range contactless technology allowing mobile devices to act primarily as either a reader or a token. Relay attacks exploit the assumption that a contactless token within communication range is in close proximity, by placing a proxy-token in range of a contactless reader and relaying communication over a greater distance to a proxy-reader communicating with the authentic token. It has been theorised that NFC-enabled mobile phones could be used as a generic relay attack platform without any additional hardware, but this has not been successfully demonstrated in practice. We present the first generic practical implementation of a contactless relay attack by using only NFC-enabled mobile phones, requiring only suitable mobile software applications. This implementation reduces the complexity of relay attacks and therefore has potential security implications for current contactless systems.
机译:非接触式技术被广泛应用于安全敏感的应用,包括识别,支付,访问控制系统。近场通信(NFC)是一种短距离非接触式技术允许移动设备以主要充当任一个读取器或令牌。中继攻击利用假定通信范围内的令牌的接触是在靠近,通过将代理令牌以非接触读写器的范围和中继通信在更大的距离,以代理阅读器与正品令牌通信。据推测,NFC功能的手机可以作为没有任何附加硬件的通用中继攻击平台,但是这并没有在实践中证明是成功。我们只使用具备NFC功能的手机,只需要合适的移动应用软件呈现出非接触式中继攻击的第一个通用的实际应用。此实现降低的中继攻击的复杂性,因此对目前的非接触式系统的潜在安全隐患。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号