首页> 外文会议>USENIX Security Symposium >Keep Your Enemies Close: Distance Bounding Against Smartcard Relay Attacks
【24h】

Keep Your Enemies Close: Distance Bounding Against Smartcard Relay Attacks

机译:保持敌人关闭:距离智能卡中继攻击的距离

获取原文

摘要

Modern smartcards, capable of sophisticated cryptography, provide a high assurance of tamper resistance and are thus commonly used in payment applications. Although extracting secrets out of smartcards requires resources beyond the means of many would-be thieves, the manner in which they are used can be exploited for fraud. Cardholders authorize financial transactions by presenting the card and disclosing a PIN to a terminal without any assurance as to the amount being charged or who is to be paid, and have no means of discerning whether the terminal is authentic or not. Even the most advanced smartcards cannot protect customers from being defrauded by the simple relaying of data from one location to another. We describe the development of such an attack, and show results from live experiments on the UK's EMV implementation, Chip & PIN. We discuss previously proposed defences, and show that these cannot provide the required security assurances. A new defence based on a distance bounding protocol is described and implemented, which requires only modest alterations to current hardware and software. As far as we are aware, this is the first complete design and implementation of a secure distance bounding protocol. Future smartcard generations could use this design to provide cost-effective resistance to relay attacks, which are a genuine threat to deployed applications. We also discuss the security-economics impact to customers of enhanced authentication mechanisms.
机译:现代智能卡能够精致加密,提供了篡改阻力的高度保证,因此通常用于支付应用。虽然从智能卡中提取秘密需要资源超出许多盗贼的手段,但可以利用它们的方式进行欺诈。持卡人通过赠送卡并将PIN透露到终端披到终端,而无需任何保证金或将要支付的金额或者才能挑战终端是真实的。即使是最先进的智能卡也无法保护客户免受从一个位置的简单中继数据欺骗。我们描述了这种攻击的发展,并展示了英国EMV实现,芯片和引脚的实例结果。我们讨论先前提出的防御,并表明这些不能提供所需的安全保证。描述并实现了基于距离边界协议的新防御,只需要更改到当前硬件和软件的更改。据我们所知,这是第一个完整的设计和实现安全距离边界协议。未来的智能卡几代可以使用这种设计来提供对中继攻击的经济有效的阻力,这是对部署应用程序的真正威胁。我们还讨论了对增强认证机制的客户的安全经济影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号