"Internet of Smart Cards": A pocket attacks scenario

被引:4
|
作者
Sportiello, Luigi [1 ]
机构
[1] European Commiss, JRC, Ispra, Italy
关键词
Contactless Smart Card; NFC; Relay Attack; Smart Cards Botnet; ePassport; EMV Payment Card; RELAY; SECURITY; PASSPORT; PRIVACY;
D O I
10.1016/j.ijcip.2019.05.005
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Smart cards are secure devices used to store people sensitive data and to regulate important operations like identity proofs and payment transactions. For years people have been used to contact smart cards but in the last decade we have seen the massive introduction of contactless smart cards. At the same time we have seen a growing number of mobile phones equipped with a NFC interface in circulation, which are capable of interacting with contactless smart cards. Under different circumstances the user's contactless cards and mobile phone are kept close together at a distance that should enable them to interact each other, for instance in pockets and bags. We describe an architecture to attack the contactless cards of a user through his NFC-equipped mobile phone. The user's mobile phone, here defined as smart-mole, is infected and connected to the NFC-equipped one of the attacker, the proxy. The victim's phone capabilities are exploited to run local attacks against a contactless card in its range, for instance to recover the card PIN that is then sent back to the attacker. Subsequently the attacker remotely uses the victim's card through a relay attack putting his phone in front of a reader and providing the PIN of the victim card when needed, basically impersonating the cardholder. Infecting several phones an attacker could have under his control a large set of cards, a sort of "Internet of Smart Cards". We show that surveying a decade of research and development in the contactless cards field such attacks look feasible according the current social context and the level of technology. We also discuss how they could be methodologically applied by an attacker to defeat the different measures currently adopted to secure contactless cards. (C) 2019 The Author. Published by Elsevier B.V.
引用
收藏
页数:15
相关论文
共 50 条
  • [41] Advances in smart cards
    Domingo-Ferrer, Josep
    Posegga, Joachim
    Sebe, Francesc
    Torra, Vicenc
    [J]. COMPUTER NETWORKS, 2007, 51 (09) : 2219 - 2222
  • [42] Smart cards for dummies
    [J]. Print Prof., 2008, 10 (58-60):
  • [43] A Smart Middleware to Detect On-Off Trust Attacks in the Internet of Things
    Caminha, Jean
    Perkusich, Angelo
    Perkusich, Mirko
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS (ICCE), 2018,
  • [44] A bi-channel voltage regulator protecting smart cards against power analysis attacks
    Telandro, Vincent
    Kussener, Edith
    Barthelemy, Herve
    Malherbe, Alexandre
    [J]. ANALOG INTEGRATED CIRCUITS AND SIGNAL PROCESSING, 2009, 59 (03) : 275 - 285
  • [45] Smart cards inside
    Gammel, BM
    Rüping, SJ
    [J]. ESSCIRC 2005: PROCEEDINGS OF THE 31ST EUROPEAN SOLID-STATE CIRCUITS CONFERENCE, 2005, : 69 - 74
  • [46] The adolescence of smart cards
    Quisquater, JJ
    [J]. FUTURE GENERATION COMPUTER SYSTEMS, 1997, 13 (01) : 3 - 7
  • [47] Healthcare information systems using digital signature and synchronized smart cards via the internet
    Song, WJ
    Ahn, BH
    Kim, WH
    [J]. INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY: CODING AND COMPUTING, PROCEEDINGS, 2002, : 177 - 182
  • [48] Laminated Pocket Cards to Teach Clinical Judgment
    Prendergast, Krista M.
    D'Alessio, Diane
    Forte, Pamela
    [J]. NURSE EDUCATOR, 2024,
  • [49] Small pocket cards, more effective means
    Noetzel, Timo
    [J]. INTERNATIONALE POLITIK, 2008, 63 (03): : 25 - 32
  • [50] Co-Simulating the Internet of Things in a Smart Grid use case scenario
    Koelsch, Johannes
    Ratzke, Axel
    Grimm, Christoph
    [J]. 2019 7TH WORKSHOP ON MODELING AND SIMULATION OF CYBER-PHYSICAL ENERGY SYSTEMS (MSCPES), 2019,