A practical experience with RFID security

  • Chun Chieh Chen*
  • , Inn Tung Chen
  • , Chen Mou Cheng
  • , Ming Yang Chih
  • , Jie Ren Shih
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

5 Scopus citations

Abstract

Radio-frequency identification (RFID) technologies allow remote identification as well as generic data access using radio waves. It is also commonly used in transportation and other payment systems, e.g., the MIFARE of NXP Semiconductors [5], one of the most widely deployed contactless smart card standards. Recently, the interest in using RFID for micro payment grows rapidly as users get used to the convenience brought by RFID, and corporations discover that RFID can significantly lower the cost of operation. However, there are security concerns, as many passive RFID technologies do not have adequate cryptographic protection. Furthermore, the communication can be eavesdropped by a third party, making RFID particularly vulnerable to all sorts of attacks. In this work, we examine the EasyCard of the Taipei Metro Rapid Transit (MRT) Corporation, a transportation ticketing system based on the MIFARE Classic technology [10]. We capture and analyze the communication between a legitimate reader and an EasyCard using GNURadio [2], an open-source software-defined radio running on PC. We will share our experiences with EasyCard security and hopefully provide some insights into RFID security in practice.

Original languageEnglish
Title of host publicationProceedings - 2009 10th International Conference on Mobile Data Management
Subtitle of host publicationSystems, Services and Middleware, MDM 2009
Pages395-396
Number of pages2
DOIs
StatePublished - 2009
Externally publishedYes
Event2009 10th International Conference on Mobile Data Management: Systems, Services and Middleware, MDM 2009 - Taipei, Taiwan
Duration: 18 05 200920 05 2009

Publication series

NameProceedings - IEEE International Conference on Mobile Data Management
ISSN (Print)1551-6245

Conference

Conference2009 10th International Conference on Mobile Data Management: Systems, Services and Middleware, MDM 2009
Country/TerritoryTaiwan
CityTaipei
Period18/05/0920/05/09

Keywords

  • Algebra attack
  • Cryptographic
  • ISO14443
  • MIFARE classic
  • RFID
  • Radio frequency
  • Security

Fingerprint

Dive into the research topics of 'A practical experience with RFID security'. Together they form a unique fingerprint.

Cite this