Subscribe to Windows IT Pro
March 14, 2008 12:00 AM

Countless RFID Cards At Risk

Windows IT Pro
InstantDoc ID #98562
Rating: (0)

Researchers have proved that cracking the cryptography of RFID cards that use Mifare Classic (Standard) integrated circuits (ICs) takes only a matter of seconds. Such cards are widely used around the world to control various types of access. The ICs were originally introduced in 1995.

In late February the Dutch government's TNO Information and Communications unit issued a warning report about the weakness of the ICs, which are used in RFID cards for access to public transportation. The warning stems from a presentation given by the Chaos Communication Club (CCC) in December 2007. During the presentation, CCC pointed out that the existence of severe weaknesses in Mifare Classic RFID card, made by NXP Semiconductors, an independent company and formerly a division of Royal Philips Electronics.

CCC's report led to further research and on March 10 "Karsten Nohl, a graduate student in the Department of Computer Science at the University of Virginia, released a report on his analysis of the cryptography used by the Mifare Classic ICs. The Dutch government had said that cracking the encryption would require $9,000 in hardware and hours of time. However, according to Nohl, a successful crack could be perfomed on a typical desktop PC in a matter of seconds.

Subsequently, the Digital Security Group (DSG) at Radboud Universiteit Nijmegen conducted further research that involved exploiting weaknesses in the encryption protocol. DSG was able to successfully retrieve cryptographic keys without the use of high-cost equipment. The researchers were then able to reproduce a copy of the card which could then be used at will. DSG published a video on YouTube (seen below) that demonstrates the ease of the attack. DSG also issued a press release about its work.

According to NXP, there are over 200 million Mifare Classic ICs in use around the world. However, a related story by the Associated Press claimed that "2 million cards in the Netherlands and a billion globally" use the ICs.

Related Content:

ARTICLE TOOLS

Comments
  • jinmuyu
    9 months ago
    Aug 26, 2011

    RFID reader MR800 series for reader/writer with the popular ARM7 microprocessors are of rapid & stable, reliable operation and beautiful appearance. User can choose freely if with the LCD display modul(128x64). They support boot screen & idle screen set and picture storage etc. The interface is USB PC/SC. They can be directly used the Windows operating system with driver and the API functions. The development cycle simple and short. The reader not only supports series IC cards according to ISO14443 TypeA/B, ISO15693 but also SAM cards compliant with ISO7816 (T=0 and T=1).

    Qualifications:
    PCD: NXP RC531, RC632; RC400, RC500(select)
    Working frequency: 13.56MHz
    RF standard: ISO14443A, ISO14443B, ISO15693
    Operating distance: 100mm (Mifare One, typical distance)
    SAM card slot: 2 slots, (supports ISO7816 T=0 and T=1)
    Interface: USB PC/SC
    Power supply: USB DC5V
    Power consumption: 0.9W
    LED: four LED (red, green, blue, yellow)
    Dimension: 123mm × 88mm × 25mm
    Weight: About 200g
    Operating temperature: -25 ~ +85 (-77 ~ +185°F)
    Storage temperature: -40 ~ +125 (-104 ~ +257°F)
    PC software: PTransWin, download
    SDK&Program: VC, VB, C++ Builder, DELPHI, Power Builder, download
    Manual: download

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.