Download WILCOX-THESIS-2015 - OAKTrust Home
Transcript
described as a relay attack however. This is more of a true man-in-the-middle or just store and replay attack. This type of security vulnerability has already been seen in attacks such as ticket cloning [7]. Even a replay attack for passport control was discussed and is vulnerable [30], but again, this is a replay, not a relay attack. The UID, which is supposed to uniquely identify each tag or other NFC communication participant, can not be used in any security protocol, as it can be faked or manipulated. With custom made equipment, attack windows can be extended through waiting-time extensions and bit faults up to very large amounts of time in which to perform attacks [31]. To add to security a user behavioral profile can be created and updated on mobile devices [1]. These profiles monitor a users normal activity. Once created they can compare the current activity with the profile and perform a security risk assessment based on that activity. This could create additional authentication needs, such as requiring a pin to be entered to activate functions considered unusual for that user. This kind of detection and profiling, called active authentication, is still in the early stages of development but shows promise. Additional prevention techniques also include gesture recognition and position data [45]. These methods use the device location to verify close proximity to the actual reader for security. Malicious software installed onto devices could even take advantage of the NFC technology, and software-based attacks could be activated, without the victim’s knowledge [45]. Google Wallet [18] provides users with a convenient method to store credit card data and uses NFC by only carrying their phones, but software based attacks can create vulnerabilities in programs like this [40]. In addition, these contactless payment methods provide no protection against relay attacks. There have been more extreme techniques suggested, such as enclosing readers 16