Presentation 2010-03-05
A Reader Only Attack on a MIFARE Classic
Satoru IMAMURA, Takashi KITAGAWA, Hideki IMAI,
PDF Download Page PDF download Page Link
Abstract(in Japanese) (See Japanese page)
Abstract(in English) MIFARE Classic card is a contactless smart card which is one of the most popular on the market. For example, it is used for payment systems for public transport or access control system of buildings, and so on. In 2008, an attack technique for extracting the private key from a legitimate card reader was proposed by Gracia et al. However, their method needs 4096 authentications between fake MIFARE cards and a legitimate reader in the worst case. In this paper, we propose another attack for extracting the secret key of a MIFARE Classic. In our attack, the attacker uses a fake card and make an authentication session with the legitimate reader. The attacker can obtain 4096 candidates of the secret key. We further discuss how much the candidate keys can be reduced if the attacker makes multiple authentication sessions.
Keyword(in Japanese) (See Japanese page)
Keyword(in English) MIFARE Classic / RFID / ISO-14443 Type-A
Paper # IT2009-108,ISEC2009-116,WBS2009-87
Date of Issue

Conference Information
Committee ISEC
Conference Date 2010/2/25(1days)
Place (in Japanese) (See Japanese page)
Place (in English)
Topics (in Japanese) (See Japanese page)
Topics (in English)
Chair
Vice Chair
Secretary
Assistant

Paper Information
Registration To Information Security (ISEC)
Language JPN
Title (in Japanese) (See Japanese page)
Sub Title (in Japanese) (See Japanese page)
Title (in English) A Reader Only Attack on a MIFARE Classic
Sub Title (in English)
Keyword(1) MIFARE Classic
Keyword(2) RFID
Keyword(3) ISO-14443 Type-A
1st Author's Name Satoru IMAMURA
1st Author's Affiliation Faculty of Science and Engineering, Chuo University()
2nd Author's Name Takashi KITAGAWA
2nd Author's Affiliation Institute of Industrial Science, The University of Tokyo:Research and Development Initiative
3rd Author's Name Hideki IMAI
3rd Author's Affiliation Faculty of Science and Engineering, Chuo University:Research Center for Information Security (RCIS), National Institute of Advanced Industrial Sciece and Technology (AIST)
Date 2010-03-05
Paper # IT2009-108,ISEC2009-116,WBS2009-87
Volume (vol) vol.109
Number (no) 445
Page pp.pp.-
#Pages 6
Date of Issue