Lock It and Still Lose It - On the (In) Security of Automotive Remote Keyless Entry Systems

被引:0
|
作者
Garcia, Flavio D. [1 ]
Oswald, David [1 ]
Kasper, Timo [2 ]
Pavlides, Pierre [1 ]
机构
[1] Univ Birmingham, Sch Comp Sci, Birmingham B15 2TT, W Midlands, England
[2] Kasper & Oswald GmbH, Bochum, Germany
关键词
KEELOQ;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
While most automotive immobilizer systems have been shown to be insecure in the last few years, the security of remote keyless entry systems (to lock and unlock a car) based on rolling codes has received less attention. In this paper, we close this gap and present vulnerabilities in keyless entry schemes used by major manufacturers. In our first case study, we show that the security of the keyless entry systems of most VW Group vehicles manufactured between 1995 and today relies on a few, global master keys. We show that by recovering the cryptographic algorithms and keys from electronic control units, an adversary is able to clone a VW Group remote control and gain unauthorized access to a vehicle by eavesdropping a single signal sent by the original remote. Secondly, we describe the Hitag2 rolling code scheme (used in vehicles made by Alfa Romeo, Chevrolet, Peugeot, Lancia, Opel, Renault, and Ford among others) in full detail. We present a novel correlation-based attack on Hitag2, which allows recovery of the cryptographic key and thus cloning of the remote control with four to eight rolling codes and a few minutes of computation on a laptop. Our findings affect millions of vehicles worldwide and could explain unsolved insurance cases of theft from allegedly locked vehicles.
引用
收藏
页码:929 / 944
页数:16
相关论文
共 50 条
  • [1] Bulk Current Injection Assessment of Automotive Remote Keyless Entry Systems
    Deroy, Patrick
    Barchanski, Andreas
    Rostamzadeh, Cyrous
    Jones, Christopher
    Frost, Ryan
    Grobosky, Michael
    Englefield, Chris
    Grassi, Flavia
    Pignari, Sergio A.
    [J]. 2017 IEEE INTERNATIONAL SYMPOSIUM ON ELECTROMAGNETIC COMPATIBILITY & SIGNAL/POWER INTEGRITY (EMCSI), 2017, : 660 - 664
  • [2] A Novel Link Budget Approach for the Analysis of Automotive Remote Keyless Entry Systems
    El-Makhour, Raed
    Lardjane, Eric
    Siguier, Gregory
    Kessler, Sebastien
    [J]. 2013 IEEE 78TH VEHICULAR TECHNOLOGY CONFERENCE (VTC FALL), 2013,
  • [3] Wireless Attacks on Automotive Remote Keyless Entry Systems [Invited Keynote Talk Abstract]
    Oswald, David
    [J]. TRUSTED'16: PROCEEDINGS OF THE INTERNATIONAL WORKSHOP ON TRUSTWORTHY EMBEDDED DEVICES, 2016, : 43 - 44
  • [4] Simple keyless entry lock
    Sullivan, B
    [J]. ELECTRONICS WORLD, 2000, 106 (1774): : 808 - 808
  • [5] Applied automotive mechatronics - Case study remote keyless entry system
    Michaelsen, M
    [J]. ELECTRONIC SYSTEMS FOR VEHICLES, 1998, 1415 : 149 - 168
  • [6] RollBack: A New Time-Agnostic Replay Attack Against the Automotive Remote Keyless Entry Systems
    Csikor, Levente
    Lim, Hoon Wei
    Wong, Jun Wen
    Ramesh, Soundarya
    Parameswarath, Rohini Poolat
    Chan, Mun Choon
    [J]. ACM TRANSACTIONS ON CYBER-PHYSICAL SYSTEMS, 2024, 8 (01)
  • [7] RollBack: A New Time-Agnostic Replay Attack Against the Automotive Remote Keyless Entry Systems
    Csikor, Levente
    Lim, Hoon Wei
    Wong, Jun Wen
    Ramesh, Soundarya
    Parameswarath, Rohini Poolat
    Chan, Mun Choon
    [J]. arXiv, 2022,
  • [8] Robustness of Remote Keyless Entry Systems to Intentional Electromagnetic Interference
    van de Beek, Stefan
    Vogt-Ardatjew, Robert
    Leferink, Frank
    [J]. 2014 INTERNATIONAL SYMPOSIUM ON ELECTROMAGNETIC COMPATIBILITY (EMC EUROPE), 2014, : 1242 - 1245
  • [9] On Determination of Conducted RF Immunity Test Methodology for Automotive Remote Keyless Entry Receivers
    Rostamzadeh, Cyrous
    Pavatich, Frank
    [J]. 2008 IEEE INTERNATIONAL SYMPOSIUM ON ELECTROMAGNETIC COMPATIBILITY, VOLS 1-3, 2008, : 153 - 158
  • [10] A Quantum Safe Authentication Protocol for Remote Keyless Entry Systems in Cars
    Parameswarath, Rohini Poolat
    Abhishek, Nalam Venkata
    Sikdar, Biplab
    [J]. 2023 IEEE 98TH VEHICULAR TECHNOLOGY CONFERENCE, VTC2023-FALL, 2023,