• DocumentCode
    2920179
  • Title

    How to develop clairaudience - active eavesdropping in passive RFID systems

  • Author

    Qi Chai ; Guang Gong ; Engels, D.

  • Author_Institution
    Dept. of Electr. & Comput. Eng., Univ. of Waterloo, Waterloo, ON, Canada
  • fYear
    2012
  • fDate
    25-28 June 2012
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    The large operation range of passive RFID systems and the ubiquitous deployment of passive tags introduce growing security and privacy threats such as tag skimming/tracking/cloning, in which eavesdropping the communication between the legitimate reader and the victim tag to obtain raw data is a basic tool for the adversary. However, given the fundamentality of eavesdropping, there are limited work investigating its intension/extension for passive RFID systems. In this work, we identify a brand-new attack at physical layer, called Unidirectional Active Eavesdropping, which defeats the customary impression that eavesdropping is a “passive” attack. In this attack, the adversary transmits an un-modulated carrier at a certain frequency, while a valid reader and a tag interacts at another frequency. When a passive tag modulates the amplitude of reader´s signal, it causes fluctuations on the blank carrier as well. By carefully examining the amplitude of the backscattered version of both blank carrier and reader´s carrier, the eavesdropper is able to recognize tag´s responses more confidently. Besides the formalization and the theoretic analysis, we set out to fill the literature´s gap by demonstrating this new attack towards a popular family of passive RFID systems, namely EPCglobal UHF Class-1 Gen-2, using software-defined radio devices and a programmable passive tag. Our empirically results further confirm that the active eavesdropping achieves a significant improvement in the reliability of the intercepted communication.
  • Keywords
    radiofrequency identification; software radio; telecommunication network reliability; telecommunication security; EPCglobal UHF Class-1 Gen-2; blank carrier; clairaudience-active eavesdropping; intercepted communication reliability; passive RFID systems; passive attack; passive tags; physical layer; privacy threats; programmable passive tag; reader carrier; software-defined radio devices; unidirectional active eavesdropping; Radiofrequency identification; Receivers; Reliability theory; RFID systems; active eavesdropping; passive tags;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    World of Wireless, Mobile and Multimedia Networks (WoWMoM), 2012 IEEE International Symposium on a
  • Conference_Location
    San Francisco, CA
  • Print_ISBN
    978-1-4673-1238-7
  • Electronic_ISBN
    978-1-4673-1237-0
  • Type

    conf

  • DOI
    10.1109/WoWMoM.2012.6263770
  • Filename
    6263770