• DocumentCode
    588208
  • Title

    Handling the NDEF signature record type in a secure manner

  • Author

    Korak, Thomas ; Wilfinger, L.

  • Author_Institution
    Inst. for Appl. Inf. Process. & Commun. (IAIK), Graz Univ. of Technol., Graz, Austria
  • fYear
    2012
  • fDate
    5-7 Nov. 2012
  • Firstpage
    107
  • Lastpage
    112
  • Abstract
    Today´s society is used to get information of different types of items in a fast and convenient way using e.g., a camera or a barcode scanner in combination with the Internet. Using near-field communication (NFC) this information procurement can be further simplified. The desired information is obtained by just touching a so-called NFC tag with an NFC-capable device (e.g. smartphone). Of course also new opportunities for attackers rise with this technology, the content of the tags can be changed in order to provide wrong information. The NFC Forum has addressed this issue by introducing digital signatures on the NFC tags. In this work we have used a state-of-the-art smartphone with NFC functionality and Android operating system in order to point out different security vulnerabilities which rise even with signed tags. Using a self-developed Android application that handles the digital signatures on NFC tags, we could show these security vulnerabilities in real-world examples. Our achieved results show that the integration of a digital signature on NFC tags is not enough to provide integrity and authenticity of the data. Also the handling of data has to be done with great care. Suggestions for creating signed tags in a secure way are also given in the result section.
  • Keywords
    digital signatures; near-field communication; operating systems (computers); smart phones; telecommunication security; Android operating system; Internet; NDEF signature record type; NFC tag; NFC-capable device; barcode scanner; camera; data authentication; digital signatures; near-field communication; security vulnerability; smartphone; Androids; Browsers; Google; Humanoid robots; Payloads; Security; Smart phones;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    RFID-Technologies and Applications (RFID-TA), 2012 IEEE International Conference on
  • Conference_Location
    Nice
  • Print_ISBN
    978-1-4673-4656-6
  • Electronic_ISBN
    978-1-4673-4658-0
  • Type

    conf

  • DOI
    10.1109/RFID-TA.2012.6404492
  • Filename
    6404492