Download WILCOX-THESIS-2015 - OAKTrust Home

Transcript
described as a relay attack however. This is more of a true man-in-the-middle or just
store and replay attack. This type of security vulnerability has already been seen
in attacks such as ticket cloning [7]. Even a replay attack for passport control was
discussed and is vulnerable [30], but again, this is a replay, not a relay attack.
The UID, which is supposed to uniquely identify each tag or other NFC communication participant, can not be used in any security protocol, as it can be faked
or manipulated. With custom made equipment, attack windows can be extended
through waiting-time extensions and bit faults up to very large amounts of time in
which to perform attacks [31].
To add to security a user behavioral profile can be created and updated on mobile
devices [1]. These profiles monitor a users normal activity. Once created they can
compare the current activity with the profile and perform a security risk assessment
based on that activity. This could create additional authentication needs, such as
requiring a pin to be entered to activate functions considered unusual for that user.
This kind of detection and profiling, called active authentication, is still in the early
stages of development but shows promise.
Additional prevention techniques also include gesture recognition and position
data [45]. These methods use the device location to verify close proximity to the
actual reader for security.
Malicious software installed onto devices could even take advantage of the NFC
technology, and software-based attacks could be activated, without the victim’s
knowledge [45]. Google Wallet [18] provides users with a convenient method to
store credit card data and uses NFC by only carrying their phones, but software
based attacks can create vulnerabilities in programs like this [40]. In addition, these
contactless payment methods provide no protection against relay attacks.
There have been more extreme techniques suggested, such as enclosing readers
16