"Internet of Smart Cards": A pocket attacks scenario

被引:4
|
作者
Sportiello, Luigi [1 ]
机构
[1] European Commiss, JRC, Ispra, Italy
关键词
Contactless Smart Card; NFC; Relay Attack; Smart Cards Botnet; ePassport; EMV Payment Card; RELAY; SECURITY; PASSPORT; PRIVACY;
D O I
10.1016/j.ijcip.2019.05.005
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Smart cards are secure devices used to store people sensitive data and to regulate important operations like identity proofs and payment transactions. For years people have been used to contact smart cards but in the last decade we have seen the massive introduction of contactless smart cards. At the same time we have seen a growing number of mobile phones equipped with a NFC interface in circulation, which are capable of interacting with contactless smart cards. Under different circumstances the user's contactless cards and mobile phone are kept close together at a distance that should enable them to interact each other, for instance in pockets and bags. We describe an architecture to attack the contactless cards of a user through his NFC-equipped mobile phone. The user's mobile phone, here defined as smart-mole, is infected and connected to the NFC-equipped one of the attacker, the proxy. The victim's phone capabilities are exploited to run local attacks against a contactless card in its range, for instance to recover the card PIN that is then sent back to the attacker. Subsequently the attacker remotely uses the victim's card through a relay attack putting his phone in front of a reader and providing the PIN of the victim card when needed, basically impersonating the cardholder. Infecting several phones an attacker could have under his control a large set of cards, a sort of "Internet of Smart Cards". We show that surveying a decade of research and development in the contactless cards field such attacks look feasible according the current social context and the level of technology. We also discuss how they could be methodologically applied by an attacker to defeat the different measures currently adopted to secure contactless cards. (C) 2019 The Author. Published by Elsevier B.V.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] SMART CARDS - MORE POWER TO YOUR POCKET
    STEINER, A
    [J]. ELECTRONICS AND POWER, 1987, 33 (04): : 232 - 232
  • [2] Vulnerabilities and Attacks in a Smart Buildings Scenario
    Seferi, Rifat
    Giangiacomi, Sofia
    Berberi, Kejdi
    [J]. 2019 IEEE 23RD INTERNATIONAL SYMPOSIUM ON CONSUMER TECHNOLOGIES (ISCT), 2019, : 296 - 298
  • [3] Side channel attacks on Smart Cards: Threats & countermeasures
    Krieger, U
    [J]. SECURING ELECTRONIC BUSINESS PROCESSES, 2004, : 73 - 81
  • [4] Evaluation of Countermeasures Against Fault Attacks on Smart Cards
    Sere, Ahmadou A.
    Iguchi-Cartigny, Julien
    Lanet, Jean-Louis
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2011, 5 (02): : 49 - 60
  • [5] Prediction of RFID Systems Coverage Applied to Smart Cards Scenario
    Berz, Everton L.
    Hessel, Fabiano P.
    de Azambuja, Marcelo C.
    Ody, Julio C.
    [J]. 2012 IEEE 23RD INTERNATIONAL SYMPOSIUM ON PERSONAL INDOOR AND MOBILE RADIO COMMUNICATIONS (PIMRC), 2012, : 1484 - 1490
  • [6] Wireless Internet payment system using smart cards
    Dandash, O
    Wu, XP
    Le, PD
    [J]. ITCC 2005: INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY: CODING AND COMPUTING, VOL 2, 2005, : 16 - 21
  • [7] Scenario based performance optimisation in face verification using smart cards
    Bourlai, T
    Messer, K
    Kittler, J
    [J]. AUDIO AND VIDEO BASED BIOMETRIC PERSON AUTHENTICATION, PROCEEDINGS, 2005, 3546 : 289 - 300
  • [8] Randomized execution algorithms for smart cards to resist power analysis attacks
    Zhang, Daigu
    Liao, Xiaofeng
    Qiu, Meikang
    Hu, Jingtong
    Sha, Edwin H. -M.
    [J]. JOURNAL OF SYSTEMS ARCHITECTURE, 2012, 58 (10) : 426 - 438
  • [9] An Improved Authentication Protocol Using Smart Cards for the Internet of Things
    Cao Shouqi
    Liu Wanrong
    Cao Liling
    He Xin
    Ji Zhiyong
    [J]. IEEE ACCESS, 2019, 7 : 157284 - 157292
  • [10] Protection circuit against differential power analysis attacks for smart cards
    Muresan, Radu
    Gregori, Stefano
    [J]. IEEE TRANSACTIONS ON COMPUTERS, 2008, 57 (11) : 1540 - 1549