论文标题
NFCGATE:使用基于智能手机的工具包为NFC安全研究打开大门
NFCGate: Opening the Door for NFC Security Research with a Smartphone-Based Toolkit
论文作者
论文摘要
近场通信(NFC)用于从访问控制到付款系统的各种关键安全应用程序中。但是,NFC协议分析通常需要昂贵或明显的专用硬件,或者在智能手机上受到严重限制。 2015年,NFCGATE的概念证明旨在通过使用现成的Android智能手机提供NFC分析的功能来解决此问题。 在本文中,我们基于功能有限的原始开源代码库提供了扩展和改进的NFC工具包。借助机上流量分析和修改,继电器和重播功能,该工具包将现成的智能手机变成了功能强大的NFC研究工具。为了支持针对中继攻击的对策的开发,我们研究了NFCGATE在不同配置中产生的潜伏期。 我们新实施的功能和改进能够从著名的欧洲锁供应商中获得屡获殊荣的企业级NFC锁的案例研究,否则该供应商将需要专用的硬件。对锁的分析揭示了几个安全问题,这些问题已透露给供应商。
Near-Field Communication (NFC) is being used in a variety of security-critical applications, from access control to payment systems. However, NFC protocol analysis typically requires expensive or conspicuous dedicated hardware, or is severely limited on smartphones. In 2015, the NFCGate proof of concept aimed at solving this issue by providing capabilities for NFC analysis employing off-the-shelf Android smartphones. In this paper, we present an extended and improved NFC toolkit based on the functionally limited original open-source codebase. With in-flight traffic analysis and modification, relay, and replay features this toolkit turns an off-the-shelf smartphone into a powerful NFC research tool. To support the development of countermeasures against relay attacks, we investigate the latency incurred by NFCGate in different configurations. Our newly implemented features and improvements enable the case study of an award-winning, enterprise-level NFC lock from a well-known European lock vendor, which would otherwise require dedicated hardware. The analysis of the lock reveals several security issues, which were disclosed to the vendor.