Authentication Issues in Near Field Communication and RFID
Total Page:16
File Type:pdf, Size:1020Kb
Authentication Issues in Near Field Communication and RFID Submitted by Muhammad Qasim Saeed for the degree of Doctor of Philosophy of the Royal Holloway, University of London 2014 Declaration I, Muhammad Qasim Saeed, hereby declare that this thesis and the work presented in it is entirely my own. Where I have consulted the work of others, this is always clearly stated. Signed . (Muhammad Qasim Saeed) Date: 1 To Eve, who enjoys the most powerful status in information security. 2 Abstract Near Field Communication is a short-range wireless technology based on RFID stan- dard ISO 18092, ISO 14443 and ISO 15693. This means, it provides compatibility with the millions of contactless smartcards and RFID scanners that already exist worldwide. NFC is now available on the phones and this integration has resulted in a sharp rise in its utility. An NFC-enabled cell phone acts as an RFID reader to read compatible RFID tags (NFC tags), such as smart posters. The same cell phone can also be used as an NFC tag storing relevant data. In this case, a cell phone transforms into a digital wallet storing bank cards (money), vouchers, loyalties card etc., at a secure place called `Secure Element'. Abuse of NFC technology is also on sharp rise because of large num- ber of users and inadequate security standards. This thesis looks at security issues of NFC and RFID and provides mechanisms to improve the security features. NFC Fo- rum (an association for developing NFC standards) released the signature specification in 2010 describing rules to digitally sign the NFC tag's contents. A part of the thesis covers the security related issues of the signature specification. Later in the thesis, a new specification for authenticating an NFC tag is proposed, including a framework of its implementation in a supply chain in order to detect counterfeit products. The thesis also includes a framework for NFC mobile wallet, where the Secure Element in the cell phone is only used for customer authentication and the banking credentials are stored in a cloud. At the end of the thesis, security analysis of an authentication protocol for low-cost RFID tags is described with multiple attacks resulting in full disclosure of secret keys. 3 Acknowledgement Completion of this doctoral dissertation was possible with the support of several peo- ple. I would like to express my sincere gratitude to all of them. First of all, I am extremely grateful to my research supervisor, Dr. Colin Walter, Director of Distance Learning, Information Security Group (ISG), Royal Holloway University of London, for his valuable guidance, scholarly inputs and consistent encouragement I received throughout the research work. He always made himself available to clarify my doubts despite his busy schedules and I consider it as a great opportunity to do my doctoral programme under his guidance and to learn from his research expertise. Thank you Dr. Colin Walter, for all your help and support. Some faculty members of the ISG have been very kind enough to extend their help at various phases of this research, whenever I approached them, and I do hereby acknowledge all of them. I thank Dr. Kostantinos Markantonakis, Smart Card Centre, ISG, Royal Holloway University of London for providing me the expert opinions related to my area of research. I thank Dr. Gerhard Hancke for his valuable suggestions and concise comments about my work. I also thank Dr. Carlos Cid and Dr. Chez Ciechanowicz for their kind support during my annual reviews. I would like to thank Prof. Keith Martin, Director ISG, Royal Holloway University of London for providing me the financial support whenever I needed. It was all because of his support that I was able to attend academic conferences all over the world to share and gain knowledge. The thesis would not have come to a successful completion, without the help I received from the staff of the ISG. I would like to thank Jon Hart, Tristan Findley and Lisa Nixon for their support related to IT services. I also thank Guillaume Subra, Emma Mosley and Jenny Lee for providing me the administrative support. I am thankful to my colleague, Zeeshan Bilal, for many fruitful discussions, ex- changing innovative ideas and scholarly interactions. I would like to thank the Government of Pakistan for sponsoring my studies and my stay in London. I owe a lot to my parents who encouraged and helped me at every stage of my personal and academic life, and longed to see this achievement come true. I am very much indebted to my family, my wife Misbah Fatima, daughters Fakiha and Duhaa, who supported me in every possible way to see the completion of this work. Above all, I owe it all to Almighty God for granting me the wisdom, health and strength to undertake this research task and enabling me to its completion. 4 Contents I Background 17 1 Background to RFID and NFC Technologies 18 1.1 Introduction.................................. 18 1.2 Power for Passive RFID Tags........................ 19 1.2.1 Far-Field RFID Tags......................... 19 1.2.2 Near-Field RFID Tags........................ 20 1.3 Near Field Communication......................... 21 1.3.1 NFC on Cell Phones......................... 22 1.3.2 Gartner Hype Cycle for NFC.................... 25 1.4 Security Concerns.............................. 26 2 The NFC Forum 28 2.1 Introduction.................................. 28 2.2 NFC Forum Tags............................... 29 2.3 NFC Forum Specifications.......................... 29 2.3.1 NFC Data Exchange Format.................... 30 2.3.2 Signature Record Type Definition................. 32 2.4 Summary................................... 35 II Some Contributions 37 3 Attacks on NDEF Specification 38 3.1 Introduction.................................. 38 3.1.1 Our Contribution........................... 39 3.2 The Amended Record Composition Attack................. 39 3.3 Record Decomposition Attack........................ 41 3.4 Countermeasures............................... 42 3.4.1 Countermeasure I.......................... 43 5 3.4.2 Countermeasure II.......................... 49 3.5 Comments on the Candidate Signature Specification V2.0........ 51 3.6 Conclusion.................................. 53 4 Off-line NFC Tag Authentication 54 4.1 Introduction.................................. 54 4.2 Tag Authentication Scenarios........................ 55 4.2.1 On-line Authentication....................... 56 4.2.2 Off-line Authentication....................... 57 4.3 NFC Tag Authentication........................... 58 4.4 Proposed Tag Authentication Scheme................... 59 4.4.1 The Tag Authentication Digital Certificate............ 60 4.4.2 The Tag Authentication Record................... 61 4.4.3 The Supplementary Text Field................... 61 4.4.4 Protocol Execution Sequence.................... 62 4.5 Analysis.................................... 62 4.5.1 Backward Compatibility....................... 64 4.5.2 Implementation Issues........................ 64 4.5.3 EMV Card Authentication Model................. 65 4.5.4 Tag Message as a Digital Certificate................ 66 4.5.5 Strengths and Weaknesses...................... 67 4.6 Conclusion.................................. 68 5 Consumer-Level Counterfeit Detection Framework 69 5.1 Introduction.................................. 69 5.1.1 Our Contribution........................... 72 5.2 EPC in the Supply Chain.......................... 73 5.3 Related Work................................. 74 5.3.1 The Alex Arbit et al Anti-Counterfeiting Model......... 74 5.3.2 Weaknesses.............................. 75 5.4 The Proposed Model............................. 76 5.4.1 Initialisation Phase.......................... 77 5.4.2 Verification Phase.......................... 78 5.5 Analysis.................................... 79 5.5.1 Justification for Two RFID Tags.................. 80 5.5.2 Security Analysis........................... 80 5.5.3 Mobile Phone Security........................ 82 5.5.4 Economic Analysis.......................... 82 6 5.6 Conclusion.................................. 85 6 An NFC Payment Framework 87 6.1 Introduction.................................. 87 6.2 Mobile Commerce Using NFC........................ 88 6.2.1 GSM Authentication......................... 89 6.2.2 Conventional Payment Structures.................. 89 6.2.3 Advantages of the Cloud-Based Approach............. 90 6.3 The Protocol Version I............................ 92 6.4 The Protocol Version II........................... 92 6.4.1 Phase I: Customer Identification and Credit Check........ 95 6.4.2 Phase II: Customer Authentication................. 96 6.4.3 Phase III: Transaction Execution.................. 97 6.5 Analysis.................................... 98 6.5.1 Dishonest Customer......................... 99 6.5.2 A Dishonest Shop.......................... 101 6.5.3 Message Security........................... 101 6.5.4 Monetary Transaction Between Two Individuals......... 104 6.5.5 Comparison of Proposed and Conventional Framework...... 104 6.6 Conclusion.................................. 104 7 Attacks on Authentication Protocols 106 7.1 Introduction.................................. 106 7.2 Authentication in RFIDs........................... 107 7.3 Two Ultra-lightweight Authentication Protocols.............. 108 7.3.1 Static Identity Protocol for RFID (SIDRFID) ........... 108 7.3.2 Dynamic Identity Protocol for RFID (DIDRFID)......... 110 7.4 Security Analysis of SIDRFID ........................ 112 7.4.1 Passive Hamming Weight Disclosure (PHWD) Attack.....