[go: up one dir, main page]
More Web Proxy on the site http://driver.im/ skip to main content
10.1109/SPW.2013.29guideproceedingsArticle/Chapter ViewAbstractPublication PagesConference Proceedingsacm-pubtype
Article

On Bad Randomness and Cloning of Contactless Payment and Building Smart Cards

Published: 23 May 2013 Publication History

Abstract

In this paper we study the randomness of some random numbers found in real-life smart card products. We have studied a number of symmetric keys, codes and random nonces in the most prominent contactless smart cards used in buildings, small payments and public transportation used by hundreds of millions of people every day. Furthermore we investigate a number of technical questions in order to see to what extent the vulnerabilities we have discovered could be exploited by criminals. In particular we look at the case MiFare Classic cards, of which some two hundred million are still in use worldwide. We have examined some 50 real-life cards from different countries to discover that it is not entirely clear if what was previously written about this topic is entirely correct. These facts are highly relevant to the practical feasibility of card cloning in order to enter some buildings, make small purchases or in public transportation in many countries. We also show examples of serious security issues due to poor entropy with another very popular contactless smart card used in many buildings worldwide.

Cited By

View all
  • (2022)The Challenges of IoT, TLS, and Random Number Generators in the Real WorldQueue10.1145/354693320:3(18-40)Online publication date: 18-Jul-2022
  • (2016)Design and Implementation of Warbler Family of Lightweight Pseudorandom Number Generators for Smart DevicesACM Transactions on Embedded Computing Systems10.1145/280823015:1(1-28)Online publication date: 20-Feb-2016

Recommendations

Comments

Please enable JavaScript to view thecomments powered by Disqus.

Information & Contributors

Information

Published In

cover image Guide Proceedings
SPW '13: Proceedings of the 2013 IEEE Security and Privacy Workshops
May 2013
180 pages
ISBN:9780769550176

Publisher

IEEE Computer Society

United States

Publication History

Published: 23 May 2013

Author Tags

  1. HID Prox
  2. HID iClass
  3. MiFare Classic
  4. RFID
  5. Random Number Generators (RNG)
  6. building access control
  7. contactless payments
  8. cryptography
  9. human factors
  10. smart cards

Qualifiers

  • Article

Contributors

Other Metrics

Bibliometrics & Citations

Bibliometrics

Article Metrics

  • Downloads (Last 12 months)0
  • Downloads (Last 6 weeks)0
Reflects downloads up to 15 Jan 2025

Other Metrics

Citations

Cited By

View all
  • (2022)The Challenges of IoT, TLS, and Random Number Generators in the Real WorldQueue10.1145/354693320:3(18-40)Online publication date: 18-Jul-2022
  • (2016)Design and Implementation of Warbler Family of Lightweight Pseudorandom Number Generators for Smart DevicesACM Transactions on Embedded Computing Systems10.1145/280823015:1(1-28)Online publication date: 20-Feb-2016

View Options

View options

Media

Figures

Other

Tables

Share

Share

Share this Publication link

Share on social media