论文标题

你付账单!用被动继电器攻击NFC

You foot the bill! Attacking NFC with passive relays

论文作者

Sun, Yuyi, Kumar, Swarun, He, Shibo, Chen, Jiming, Shi, Zhiguo

论文摘要

想象一下,当您在商店中排队时,您面前的人可以通过使用一种被动可穿戴设备来付费,该设备强制扫描信用卡而没有您的意识。当今近场通信(NFC)启用卡的一个重要假设是商业读取器和NFC卡之间的沟通范围有限 - 低于5〜cm的距离。攻击此假设的先前方法有效地使用手机和主动继电器来扩大通信范围,以攻击NFC卡。但是,这些方法需要在对手方面的电源,并且在移动电话或主动继电器传输NFC信号时很容易定位。 我们提出了后坐力,该系统使用可穿戴的被动继电器来攻击NFC卡,通过将通信范围扩展到49.6厘米,比其预期的商业距离提高了十倍。后坐力是一种磁耦合的谐振无线功率传递系统,它通过搜索最佳几何参数来优化能量传输。具体而言,我们首先合理地缩小了可行区域,并设计后退剂菌落算法,以使继电器吸收读者的最大能量。为了重新路由信号通过人体的表面,我们通过仔细分析两个线圈之间的距离和方向对相互电感的影响来设计半腰带。然后,将另外三个线圈添加到系统中,以继续扩大通信范围。最后,广泛的实验结果验证了我们的分析,表明我们的被动继电器由常见的铜线和可调电容器组成,将NFC攻击的范围扩展到49.6厘米。

Imagine when you line up in a store, the person in front of you can make you pay her bill by using a passive wearable device that forces a scan of your credit card without your awareness. An important assumption of today's Near-field Communication (NFC) enabled cards is the limited communication range between the commercial reader and the NFC cards -- a distance below 5~cm. Previous approaches to attacking this assumption effectively use mobile phones and active relays to enlarge the communication range, in order to attack the NFC cards. However, these approaches require a power supply at the adversary side, and can be easily localized when mobile phones or active relays transmit NFC signals. We propose ReCoil, a system that uses wearable passive relays to attack NFC cards by expanding the communication range to 49.6 centimeters, a ten-fold improvement over its intended commercial distance. ReCoil is a magnetically coupled resonant wireless power transfer system, which optimizes the energy transfer by searching the optimal geometry parameters. Specifically, we first narrow down the feasible area reasonably and design the ReCoil-Ant Colony Algorithm such that the relays absorb the maximum energy from the reader. In order to reroute the signal to pass over the surface of human body, we then design a half waist band by carefully analyzing the impact of the distance and orientation between two coils on the mutual inductance. Then, three more coils are added to the system to keep enlarging the communication range. Finally, extensive experiment results validate our analysis, showing that our passive relays composed of common copper wires and tunable capacitors expand the range of NFC attacks to 49.6 centimeters.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源