116
G. Avoine et al.
7.2.1 Basic Relay Strategies
A basic relay equates to the attack described in Sect. 7.1.
7.2.1.1 Purpose-Built Relays
There are several relay-attack implementations against radio frequency identification (RFID) systems using purpose-built attack proxies and relay links, which
incur minimal delay in executing the attack, e.g., [221, 256, 548]. The conventional
approach to implementing an attack uses custom-built attack proxies, using a
combination of custom hardware and hacked readers [256, 548]. The proxy will first
demodulate the data symbols from the reader or token, and then forward data over
an analog radio link, e.g., a video channel [256], and this tends to introduce a delay
in the order of a few to tens of microseconds (2–20 µs). These implementations are
also capable of active relay attacks, equivalent to a conventional man-in-the-middle
or ‘wedge’ attack, which can modify communication with negligible additional
delay, e.g., using an FPGA to reshape analog signals in real-time [256]. If the goal
is to minimize the relay delay to less than a microsecond then the relay link can
be implemented without demodulating the data first [221, 548]. In these cases, the
proxies are either connected via a wire (120–500 ns delay), or forward data by direct
up-mixing of the LF/HF carrier onto a UHF radio carrier for transmission (120–
750 ns delay).
7.2.1.2 Off-the-Shelf Relays
It has also been shown that software-only implementations using off-the-shelf
NFC-enabled mobile devices are effective, which simplifies the attack and allows
any person with the right type of NFC-enabled mobile phone to implement a
token emulator or a reader. These attacks can therefore use a standard phone as
a proxy-reader and a second phone as a proxy-token and relay the data across
Bluetooth, WiFi or the mobile data network [222, 392, 539]. Even though such
attack implementations incur a larger attack delay (200-500 ms), these remain
effective against real systems, as was demonstrated in an attack against Google
Wallet [505]. There are an increasing number of non-mobile NFC devices, such
as the Adafruit NFC breakout board, that easily connects with embedded hardware
Arduino or Raspberry Pi, which could be used as readily available proxy platforms.
G. Avoine et al.
7.2.1 Basic Relay Strategies
A basic relay equates to the attack described in Sect. 7.1.
7.2.1.1 Purpose-Built Relays
There are several relay-attack implementations against radio frequency identification (RFID) systems using purpose-built attack proxies and relay links, which
incur minimal delay in executing the attack, e.g., [221, 256, 548]. The conventional
approach to implementing an attack uses custom-built attack proxies, using a
combination of custom hardware and hacked readers [256, 548]. The proxy will first
demodulate the data symbols from the reader or token, and then forward data over
an analog radio link, e.g., a video channel [256], and this tends to introduce a delay
in the order of a few to tens of microseconds (2–20 µs). These implementations are
also capable of active relay attacks, equivalent to a conventional man-in-the-middle
or ‘wedge’ attack, which can modify communication with negligible additional
delay, e.g., using an FPGA to reshape analog signals in real-time [256]. If the goal
is to minimize the relay delay to less than a microsecond then the relay link can
be implemented without demodulating the data first [221, 548]. In these cases, the
proxies are either connected via a wire (120–500 ns delay), or forward data by direct
up-mixing of the LF/HF carrier onto a UHF radio carrier for transmission (120–
750 ns delay).
7.2.1.2 Off-the-Shelf Relays
It has also been shown that software-only implementations using off-the-shelf
NFC-enabled mobile devices are effective, which simplifies the attack and allows
any person with the right type of NFC-enabled mobile phone to implement a
token emulator or a reader. These attacks can therefore use a standard phone as
a proxy-reader and a second phone as a proxy-token and relay the data across
Bluetooth, WiFi or the mobile data network [222, 392, 539]. Even though such
attack implementations incur a larger attack delay (200-500 ms), these remain
effective against real systems, as was demonstrated in an attack against Google
Wallet [505]. There are an increasing number of non-mobile NFC devices, such
as the Adafruit NFC breakout board, that easily connects with embedded hardware
Arduino or Raspberry Pi, which could be used as readily available proxy platforms.
