DocumentCode
3341503
Title
Potential misuse of NFC enabled mobile phones with embedded security elements as contactless attack platforms
Author
Francis, L. ; Hancke, Gerhard ; Mayes, K. ; Markantonakis, K.
Author_Institution
Inf. Security Group, R. Holloway Univ. of London, Egham, UK
fYear
2009
fDate
9-12 Nov. 2009
Firstpage
1
Lastpage
8
Abstract
In this paper we investigate the possibility that a Near Field Communication (NFC) enabled mobile phone, with an embedded Secure Element (SE), could be used as a mobile token cloning and skimming platform. We show how an attacker could use a NFC mobile phone as such an attack platform by exploiting the existing security controls of the embedded SE and the available contactless APIs. To illustrate the feasibility of these actions we also show how to practically skim and emulate certain tokens typically used in payment and access control applications with a NFC mobile phone. Although such attacks can also be implemented on other contactless platforms, such as custom-built card emulators and modified readers, the NFC-enabled mobile phone has a legitimate form factor, which would be accepted by merchants and arouse less suspicion in public. Finally, we propose several security countermeasures for NFC phones that could prevent such misuse.
Keywords
mobile radio; telecommunication security; NFC; contactless attack platforms; embedded secure element; embedded security elements; mobile phones; near field communication; security controls; Access control; Cloning; Communication system control; Hardware; Information security; Mobile communication; Mobile handsets; Motion pictures; Smart cards; Wireless communication;
fLanguage
English
Publisher
ieee
Conference_Titel
Internet Technology and Secured Transactions, 2009. ICITST 2009. International Conference for
Conference_Location
London
Print_ISBN
978-1-4244-5647-5
Type
conf
DOI
10.1109/ICITST.2009.5402513
Filename
5402513
Link To Document