• DocumentCode
    3341503
  • Title

    Potential misuse of NFC enabled mobile phones with embedded security elements as contactless attack platforms

  • Author

    Francis, L. ; Hancke, Gerhard ; Mayes, K. ; Markantonakis, K.

  • Author_Institution
    Inf. Security Group, R. Holloway Univ. of London, Egham, UK
  • fYear
    2009
  • fDate
    9-12 Nov. 2009
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    In this paper we investigate the possibility that a Near Field Communication (NFC) enabled mobile phone, with an embedded Secure Element (SE), could be used as a mobile token cloning and skimming platform. We show how an attacker could use a NFC mobile phone as such an attack platform by exploiting the existing security controls of the embedded SE and the available contactless APIs. To illustrate the feasibility of these actions we also show how to practically skim and emulate certain tokens typically used in payment and access control applications with a NFC mobile phone. Although such attacks can also be implemented on other contactless platforms, such as custom-built card emulators and modified readers, the NFC-enabled mobile phone has a legitimate form factor, which would be accepted by merchants and arouse less suspicion in public. Finally, we propose several security countermeasures for NFC phones that could prevent such misuse.
  • Keywords
    mobile radio; telecommunication security; NFC; contactless attack platforms; embedded secure element; embedded security elements; mobile phones; near field communication; security controls; Access control; Cloning; Communication system control; Hardware; Information security; Mobile communication; Mobile handsets; Motion pictures; Smart cards; Wireless communication;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Internet Technology and Secured Transactions, 2009. ICITST 2009. International Conference for
  • Conference_Location
    London
  • Print_ISBN
    978-1-4244-5647-5
  • Type

    conf

  • DOI
    10.1109/ICITST.2009.5402513
  • Filename
    5402513