CIO Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
Daily Briefing for Technology's Top Decision-Makers
Tuesday, February 9th 
Home
Enterprise Software
Enterprise Hardware
Network Security
Compliance
CRM Systems
Data Storage
Chips & Processors
Operating Systems
Communications
World Wide Web
Wireless Tech
Small Business
CIO Issues
Business Briefing
After Hours
Press Releases
 

Advertisement
Supply-Chain Management

RFID Vulnerability Exposed

RFID Vulnerability Exposed
January 31, 2005 12:04PM

Bookmark and Share
"Standards are needed for RFID security, because these types of devices are now appearing in many different forms, from passports to consumer devices," says Ari Juels, principal research scientist at RSA Laboratories. "The idea is to address weaknesses in the technology before the they become more pervasive and costly."


A vulnerability in radio-frequency ID chips could put millions of users of wireless car key tags or speed pass payment devices at risk, according to a recent study by researchers at Johns Hopkins University and RSA Laboratories.

Using a relatively simple electronic device, criminals could wirelessly probe a car key tag or payment tag and then use the information obtained from the probe to crack the cryptographic key on the tag, Ari Juels, principal research scientist at RSA, explained.

In obtaining this key, an individual could circumvent the auto-theft prevention system Relevant Products/Services in a person's car or charge gasoline purchases to the speed-pass owner's account.

TI System Tested

The vulnerability was detected in the Texas Instruments Registration and Identification System, a low-power Relevant Products/Services radio-frequency security system used worldwide. More than 150 million of these transponders are embedded in keys for newer vehicles built by major manufacturers, Juels told NewsFactor. The digital signal transponders are also inside some 6 million key chain tags used for wireless gasoline purchases.

Tech-savvy thieves could initiate either a passive or active attack on the encryption technology, Juels said. In an active attack, the perpetrator scans the speed pass or key with a rogue RFID reader, although he must be in close proximity (from a few inches to one or two feet) to the targeted device.

In the passive attack, an individual could eavesdrop on the wireless communications Relevant Products/Services between the RFID device and the reader, which could be done at distance, Juels said.

Security Standards Needed

"We want to point out that standards are needed for RFID security, because these types of devices are now appearing in many different forms, from passports to consumer devices," he said. "The idea is to address weaknesses in the technology before the they become more pervasive and costly.

Juels noted that TI is not the only provider of vulnerable RFID technology and said the company's products are better than others that offer no cryptography. The impact on supply chain RFID systems has not yet been determined, he said.

The radio-frequency ID system studied by the research team uses a passive transponder chip embedded in the key and a reader inside the car that is connected to the fuel injection system. If the reader does not recognize the transponder, the car will not start, even if the physical key inserted in the ignition is the correct one.

Easy Access

In the gasoline-purchase system studied by the researchers, a reader inside the gas pump must recognize a small key-chain tag that is waved in front of it. Upon system approval, the transaction is then charged to the tag owner's credit card.

Researchers unraveled the mathematical process used in this verification process. They then purchased a commercial microchip costing less than US$200 and programmed it to find the secret key for a gasoline purchase tag owned by one of the researchers. By linking 16 such chips together, the group cracked the secret key in about 15 minutes. They had similar success with a chip-equipped car key.

The research team recommended a program of distributing free metallic sheaths to cover radio frequency devices when they are not being used, making it more difficult for thieves to electronically steal the secret keys in the tags.

Advertisement



 Supply-Chain Management
1. Google Inks Apps Deal with Capgemini
2. New RFID Tech To Fight Retail Theft
3. For Wal-Mart, Full Speed Ahead on RFID
4. RFID Chips Vulnerable to Viruses
5. IBM Refreshes RFID Portfolio


advertisement


 Most Popular Articles
1. Facebook Users Can Get McAfee Virus Protection
2. Reporters Invited To an Apple Event Set Next Week
3. New York Times May Charge for Its Online Content
4. Adobe, Oracle Make Up for Light MS Patch Tuesday
5. Zuckerberg's Comments Unleash Firestorm of Dissent


advertisement

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  MS: Windows 7 Doesn't Hurt Battery
  Nexus One 'Support' Passes the Buck
  MS: Russian Pirates Scamming Us
  Google May Make Gmail More Social
  Analysts Expect iPad Price To Drop

 Technology Marketplace
Compliance
Stand out from other IS Professionals and increase your earning potential.®).
 
Enterprise Hardware
Now is the best time to buy a new APC Smart-UPS!
HP ProLiant G6 Servers: Perform like a superstar, Save like an accountant www.hp.com
 
Enterprise I.T.
Learn how Microsoft server upgrades can create efficiencies
Stand out from other IS Professionals and increase your earning potential.®).
 
Hardware
Find out why now is the best time to buy a new APC Smart-UPS!
 
Microsoft/Windows
Read about how to add efficiencies with Microsoft Virtualization.
 
Network Security
AT&T Synaptic Compute as a Service. Boost your power on demand.
 
Mobile Enterprise Spotlight

To Love or Not To Love: Apple iPad Pros and Cons
Now that the iPad has officially been announced, opinions are rolling in on this device that combines the features of an iPod, e-reader, and tablet PC. Will the iPad turn fewer heads than the iPhone?

Analysts See iPad Price Drop, with Some Cannibalization
Just weeks before Apple officially rolls out the iPad, financial analysts are making pricing predictions. But could the analysis itself hinder the initial demand for the pricey tablet computer?

Bar Codes Go Mobile, Get Hip Again
For decades, retailers have used patterns of black dots and lines to encode data onto products. Now, bar codes are gaining favor as an easy way for cell-phone users to view ads and other data instantly.

Advertisement
Enterprise Software Spotlight

Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.

SAP CEO Abruptly Resigns; Co-CEOs Will Take Over
Business-software maker SAP announced an abrupt strategic shift in the corporate suite with CEO Léo Apotheker resigning, to be replaced by co-CEOs Bill McDermott (left) and Jim Hagemann Snabe (right).

Cybersecurity Vendors Look Hot in 2010
Tech-security companies are poised to become Wall Street darlings this year, thanks in part to Google's tiff with China, which reinforced an already positive outlook for major security vendors.

Advertisement
Enterprise Hardware Spotlight

Microsoft Says Battery Woes Not Caused By Windows 7
Battery problems on Windows 7 machines are not caused by the operating system. That's the position of Stephen Sinofsky, head of the Windows division, in a long posting on the Windows engineering blog.

IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."

'Dead Simple, Dirt Cheap' JooJoo Tablet Shipping Soon
The JooJoo, a web-browsing tablet device that is the subject of a high-profile legal dispute, appears on track to reach buyers at the end of February, but the tablet scene has dramatically changed.

Advertisement
Enterprise Security Spotlight

Chinese Cyberattacks Seen as a Pervasive Threat
Google's accusation that e-mail accounts were hacked from China landed like a bombshell because it cast light on a problem few firms will discuss: the pervasive threat from China-based cyberattacks.

Patch Tuesday Release Will Tie Microsoft's Record
After a light start to the year, Microsoft is getting ready to dump a heavy load on the shoulders of IT administrators. On Patch Tuesday next week, Microsoft will release 13 patches.

Cybersecurity Vendors Look Hot in 2010
Tech-security companies are poised to become Wall Street darlings this year, thanks in part to Google's tiff with China, which reinforced an already positive outlook for major security vendors.

Advertisement
Navigation
CIO Today
Home/Top News | Enterprise Software | Enterprise Hardware | Network Security | Compliance | CRM Systems | Data Storage
Chips & Processors | Operating Systems | Communications | World Wide Web | Wireless Tech | Small Business | CIO Issues
Business Briefing | After Hours | Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 CIO Today. All rights reserved. Article rating technology by Blogowogo.