Radio-Frequency Identification: Difference between revisions

From Elvis Wiki
No edit summary
No edit summary
Line 159: Line 159:
Security experts and researchers often use these tools to assess and scrutinise the security of RFID systems.
Security experts and researchers often use these tools to assess and scrutinise the security of RFID systems.


= Sicherheitskontrollen für RFID {{id name="sicherheitskontrollen-für-rfid" /}}=
= Security controls for RFID=


Dieser Abschnitt behandelt Sicherheitskontrollen, die auf die meisten Implementierungen anwendbar sind. Er befasst sich nicht mit der Sicherheit von RFID-fähigen Smartcards und Zahlungssystemen. Ebenso werden keine Sicherheitskontrollen für allgemeine IT-Systeme wie Netzwerkinfrastruktur, Datenbanken und Webserver diskutiert, da diese bereits durch andere Sicherheitsanforderungen und -richtlinien abgedeckt sind. Beispielsweise sollten EPCIS-Server, die über das Internet von Handelspartnern zu-gänglich sind, durch dieselben Arten von Kontrollen geschützt werden, die für jedes andere Internet-facing System verwendet werden (z.B. Verschlüsselung sensibler Kommunikation, Zugriffskontrolle zur Verhinderung unbefugten Zugriffs auf Daten und Systeme), um die Sicherheit der durch das RFID-System gesammelten Daten zu gewähr-leisten. Richtlinien zu Themen wie IT-Server-, Anwendungs-, Datenbank- und Netzwerksicherheit sind aus vielen Quellen verfügbar, einschließlich des Computer Security Resource Center (CSRC) des NIST.
This section addresses security measures that are relevant to the majority of implementations. It fails to consider the security aspects of RFID-enabled smart cards and payment systems. Furthermore, it omits any mention of security measures pertaining to conventional IT systems, such as network infrastructure, databases, and web servers, since they are already addressed by existing security prerequisites and standards. To ensure the security of the data collected by the RFID system, it is important to protect EPCIS servers that can be accessed over the Internet by trading partners. This can be done by implementing similar controls that are used for any other system accessible over the Internet, such as encrypting sensitive communications and implementing access control measures to prevent unauthorised access to data and systems. Various sources, including NIST's Computer Security Resource Centre (CSRC), provide guidelines on areas such as IT server, application, database, and network security.


*. Gruppierung der RFID-Sicherheitskontrollen
= References =
 
**. **Management**: Eine Managementkontrolle umfasst die Aufsicht über die Sicherheit des RFID-Systems. Beispielsweise könnte das Management einer Organisation bestehende Richtlinien aktualisieren müssen, um RFID Implementierungen zu berücksichtigen, wie z.B. Sicherheitskontrollen, die für ein RF-Subsystem benötigt werden.
**. **Operationell**: Eine operationelle Kontrolle (Betriebskontrolle) beinhaltet die Aktionen, die täglich von den Systemadministratoren und Benutzern des Systems durchgeführt werden. RFID-Systeme benötigen operationelle Kontrollen, die die physische Sicherheit der Systeme und deren korrekte Nutzung sicherstellen.
**. **Technisch**: Eine technische Kontrolle verwendet Technologie, um die Aktionen, die innerhalb des Systems durchgeführt werden können, zu überwachen oder einzuschränken. RFID-Systeme benötigen aus mehreren Gründen technische Kontrollen, wie zum Beispiel den Schutz von Daten auf Tags, das Selbstzerstören von Tags und den Schutz drahtloser Kommunikation.
 
*. **Managementkontrollen** Managementkontrolle ist wichtig für Risikobeurteilung, Systemplanung und -erwerb sowie für Sicherheitszertifizierungen und Bewertungen. Im Folgenden werden die Managementkontrollen für RFID-Systeme näher erläutert.
 
**. **RFID-Nutzungsrichtlinie**:
 
***. Beschreibung der genehmigten und ungenehmigten Verwendung von RFID-Technologie.
***. Sollte mit der Datenschutzpolitik der Organisation konsistent sein.
***. Notwendig für alle Organisationen, die RFID-Technologie nutzen.
***. Stellt den Rahmen für weitere Sicherheitskontrollen dar.
***. Herausforderung besteht darin, die Einhaltung der Richtlinien zu gewähr-leisten.
**. **IT-Sicherheitsrichtlinien**:
 
***. Definieren Maßnahmen zur Erreichung von hochrangigen Sicherheitszielen.
***. Decken RFID-Subsysteme wie Netzwerk, Datenbank und Anwendungs-sicherheit ab.
***. Notwendig für alle RFID-Implementierungen, insbesondere Unternehmens-Subsysteme.
***. Bieten Anleitung für die Gestaltung und Verwaltung von RFID-Systemen.
***. Erfordern die konsequente Umsetzung und Durchsetzung.
**. **Vereinbarungen mit externen Organisationen**:
 
***. Formelle Abkommen zur Festlegung von Rollen und Verantwortlichkeiten.
***. Wichtig für RFID-Systeme, die mehrere Organisationen umfassen.
***. Reduzieren das Potenzial für Missverständnisse und Sicherheitsverletzungen.
***. Überwachung der Einhaltung durch externe Organisationen ist herausfordernd.
**. **Minimierung sensibler Daten auf Tags**:
 
***. Bevorzugt die Speicherung sensibler Daten in sicheren Unternehmenssystemen.
***. Geeignet für Anwendungen mit Tags, die sensible oder interpretierbare Daten verarbeiten.
***. Verhindert, dass Gegner Informationen durch Scannen oder Lauschen erhalten.
***. Herausforderung besteht in der Abhängigkeit von der Netzwerkverfügbarkeit.
*. **Betriebskontrollen** Betriebskontrollen umfassen verschiedene Maßnahmen, die in RFID-Systemen eingesetzt werden. Sie reichen von Zugangsbeschränkungen bis hin zur Schulung von Bedienern. Die folgenden Punkte geben einen detaillierten Überblick über diese Kontrollen.
 
**. **Physische Zugangskontrolle**:
 
***. Einschließung kritischer Bereiche mit Zäunen, Türen und Überwachungs-kameras.
***. Ziel ist es, unbefugten Zugriff auf RFID-Komponenten zu verhindern.
***. Begrenzt die Möglichkeit für Gegner, RFID-Daten zu kompromittieren.
***. Nicht anwendbar in öffentlich zugänglichen Bereichen.
**. **Angemessene Platzierung von Tags und Lesegeräten**:
 
***. Vermeidung unnötiger elektromagnetischer Strahlung.
***. Platzierung abseits von Störquellen und empfindlichen Produkten.
***. Reduziert das Risiko von Interferenzen und Datenschutzverletzungen.
**. **Sichere Entsorgung von Tags**:
 
***. Physische oder elektronische Zerstörung von Tags nach Gebrauch.
***. Verhindert, dass Gegner Zugang zu Daten erhalten.
***. Wichtig für Anwendungen mit Datenschutzrisiken.
**. **Schulung von Bedienern und Administratoren**:
 
***. Vermittlung von Fähigkeiten und Wissen zur Einhaltung von Richtlinien.
***. Wichtig für alle RFID-Implementierungen.
***. Schulungen unterstützen die korrekte Nutzung und Wartung des Systems.
**. **Informationslabel und Hinweise**:
 
***. Bereitstellung grundlegender Informationen über das RFID-System.
***. Wichtig für Anwendungen, bei denen Privatsphäre ein Anliegen ist.
***. Kommuniziert Risiken und Maßnahmen zur Risikominderung.
**. **Trennung von Aufgaben**:
 
***. Verteilung von Systemaufgaben auf verschiedene Rollen.
***. Reduziert das Risiko von Betrug und böswilligen Schäden.
***. Wichtig für Anwendungen mit hohem Wert oder internen Sicherheits-risiken.
**. **Nicht offenbarende Kennungsformate**:
 
***. Verwendung von Kennungsformaten, die keine Informationen preisgeben.
***. Verhindert, dass Gegner Informationen allein aus dem Kennungsformat gewinnen.
***. Wichtig für Anwendungen, bei denen die Identifizierung des Tags ein Geschäfts-risiko darstellt.
**. **Fallback-Identifikationssystem**:
 
***. Bereitstellung alternativer Identifizierungsmethoden bei Systemausfall.
***. Anwendbar auf alle RFID-Anwendungen.
***. Bietet Redundanz und Sicherheit in Notfällen oder bei Systemausfällen.
*. **Technische Kontrollen** Technische Kontrollen sind wesentlich für die Sicherheit von RFID-Systemen. Diese umfassen Maßnahmen zur Authentifizierung und Datenintegrität, zum Schutz der RF-Schnittstelle und zur Sicherung der auf den Tags gespeicherten Daten.
 
**. **Authentifizierung und Datenintegrität**
 
***. **Passwortauthentifizierung**: Nutzung von Passwörtern zur Kontrolle des Zugriffs auf Tags. Komplexe Passwortverwaltung und Risiken bei der Über-tragung über Funk sind Herausforderungen.
***. **HMAC (Keyed-Hash Message Authentication Code)**: Einsatz von HMAC für eine stärkere Authentifizierung und Datenintegrität. Erfordert jedoch ein effizientes Schlüsselmanagement und Rechenleistung auf dem Tag.
***. **Digitale Signaturen**: Verwendung digitaler Signaturen zur Authentifizierung von Transaktionen. Setzt eine Public-Key-Infrastruktur (PKI) voraus und ist speicheraufwendiger als andere Methoden.
**. **RF-Schnittstellenschutz**
 
***. **Cover-Coding**: Verschlüsselung der Kommunikation zwischen Lesegerät und Tag, um Eavesdropping zu verhindern.
***. **Verschlüsselung der übertragenen Daten**: Schutz der Daten während der Übertragung durch Verschlüsselung.
***. **Elektromagnetische Abschirmung**: Einsatz von Abschirmungen, um die Ausbreitung von RF-Signalen zu kontrollieren und unbefugtes Auslesen zu verhindern.
***. **Frequenzauswahl**: Wahl der geeigneten Frequenz zur Vermeidung von Störungen und zur optimalen Funkabdeckung.
***. **Anpassung der Übertragungseigenschaften**: Kontrolle über die Sendeleistung und Antennenausrichtung zur Minimierung von Interferenzen und Strahlungs-risiken.
***. **Temporäre Deaktivierung von Tags**: Möglichkeit, Tags vorübergehend zu deaktivieren, um unautorisierte Zugriffe zu verhindern.
***. **Tag-Aktivierungsschalter**: Benutzerkontrolle über die Aktivierung von Tags zur Verhinderung ungewollter Kommunikation.
***. **Tag-Abfrage** (Polling): Periodische Abfrage von Tags zur Überprüfung ihrer Anwesenheit und ihres Zustandes.
**. **Datenschutz auf Tags**
 
***. **Tag-Speicherzugriffskontrolle**: Passwortgeschützte Sperrfunktionen zur Kontrolle des Lese- und Schreibzugriffs.
***. **Verschlüsselung der Daten im Ruhezustand**: Schutz der auf dem Tag gespeicherten Daten durch Verschlüsselung.
***. **Kill-Funktion**: Möglichkeit, Tags dauerhaft zu deaktivieren, um sie vor unbefugter Verwendung zu schützen.
***. **Manipulationsschutz**: Eigenschaften von Tags, die Manipulationen erschweren oder sichtbar machen.
 
== References ==


* https://www.epc-rfid.info/rfid_tags
* https://www.epc-rfid.info/rfid_tags

Revision as of 14:58, 19 December 2023

Introduction

Radio-Frequency Identification (RFID) is a communication technology, that uses electromagnetic waves to identify and track tags. A RFID system consists out of a tag, which is attached to an object, an reader, which extracts the information of the tag and an application, that uses the gathered information.

RFID-System

Reader

A reader is responsible for initiating the communication with a tag, in case of a passive tag the reader also supplies the energy needed to operate the tag.

A reader consists out of to components:

  1. A control unit
  2. A high-frequency interface

Control Unit

The control unit is responsible for

  1. Communication with the application
  2. Communication with the tag
  3. Coding and decoding of the signal
  4. Anti-collision algorithm
  5. Encryption and decryption of data sent between reader and tag
  6. Authentication between reader and tag

High-frequency interface

The high-frequency interface is responsible for

  1. Generation of strong high-frequency signals to activate the tag and supply it with energy
  2. Modulating the transmission signal to send data to the tag
  3. Receiving the radio frequency signals transmitted by a tag and converting them back into original data

Tag

RFID tags are divided into six categories by EPC Global[1]. A tag in one category has all the capabilities of the subordinate categories. This means that tags are backward compatible

Passive tags, which have no built-in energy source and draw their energy from the reader's radio waves, are assigned to classes 0 to 3. Active tags, with their own energy source, are assigned to class 4. Class 5 is reserved for tag readers and active tags that can read other tags.

  1. Class 0: These tags are passive and work with UHF. These tags are pre-programmed in the manufacturer's factory and can no longer be reprogrammed, the information can no longer be changed.
  2. Class 1: Class 1 tags use HF radio waves. In contrast to class 0 tags, class 1 tags and higher can be programmed by the user. However, in class 1, tags can only be described once.
  3. Class 2: Unlike class 1, class 2 tags can be written to multiple times.
  4. Class 3: Read-write with integrated sensors that are able to detect parameters such as temperature, pressure and movement; can be semi-passive or active. Semi-passive means that they occupy an energy source but cannot initiate communication with other tags or readers.
  5. Class 4: Class 4 tags have their own energy source and can initiate communication with other tags or readers, so they are active tags.
  6. Class 5: Class 5 tags are the most advanced, they can transfer energy to passive tags and communicate with readers and tags of any class, so they can also be classified as readers.

Tag information

Four types of information can be stored on a transponder:

  1. Information to identify the tagged item: This category includes the identification data used to uniquely identify the tagged item. This includes user-defined fields such as bank accounts, product barcodes and prices, as well as predefined registers such as the Application Family Identifier (AFI) and the Data Storage Format Identifier (DSFID)
  2. Supplementary information on the object: Supplementary data includes further standard information such as Application Identifiers (AIs) and ANSI MH-10 Data Identifiers (DIs), which enable further differentiation and specific information on the tagged item
  3. Control data: Control data could include information about the configuration of the tag, such as the settings for the security controls, including mechanisms that restrict reads or writes to user memory blocks and special registers that contain the AFI and DSFID values
  4. Manufacturer data: The unique identifier (UID), transponder type, manufacturer and manufacturing data can be stored in this category. This information can be specific to each manufacturer and transponder type.

The first two categories, identification and supplementary information, are present on all tags as they provide essential information for identifying and supplementing the tagged item. Categories three and four, control data and manufacturer data, can vary depending on the manufacturer and contain specific information for configuring the tag and identifying the manufacturer.

RFID Attacks

In contrast to attackers on the Internet, who can always attack a machine on the Internet, a server is always online and responds to requests from all over the world, an attacker of an RFID system does not have constant access. He must be physically close to the tag that is to be read. Or must be present during a transaction. Security models must be adapted to these facts. Further more, cheap RFID tags cannot perform standard encryption.

The challenge is therefore to create a realistic security model that reflects the threats and capabilities of reality as accurately as possible.


Attack methods

Cloning

There are two different types of cloning used to attack.

  1. Simple RFID cloning: If an attacker gains physical access to an RFID tag, they can clone it. The advantage of cloning is that, unlike theft, the original tag does not have to be kept by the attacker. Since the owner can easily become aware that the original tag is missing in the event of theft, no changes are made to the tag during cloning. The cloned tag has the same access options as the original. This makes it much less likely that the victim will know that they have been victimized. Disadvantage, needs physical access to the card/tag, must copy it and then return it. There are various devices for copying the card.
  2. Distance RFID cloning: There are a large number of devices that can read and clone RFID tags at a distance. The range is limited to less than 1 meter, and the greater the range, the more expensive the devices become. There are devices that can store the read data on an SD card.


Man-in-the-middle attacks

For this attacks, the hacker positions himself between the RFID tag and the reader in order to influence or eavesdrop on the communication. We distinguish between the following attacks.

  1. Eavesdropping: An attacker can use devices or apps to intercept the communication between the RFID tag and the reader in order to capture the transmitted data.
  2. Replay attacks: In this attack, the attacker is in the vicinity of a communication between the RFID/NFC tag and a reader. The communication is recorded and can be replayed at a later time to the reader.
  3. Relay attack: In a relay attack, the communication between the RFID tag and reader is recorded and sent to a third device.


Data manipulation

An attacker who has access to an RFID/NFC device manipulates it so that false data or requests are sent.


Skimming

Skimming is the use of unauthorized readers to retrieve data from RFID tags or to start a transaction, for example with a mobile wallet.


Spoofing

The attacker creates fake RFID tags or readers to fool the system and gain unauthorized access.


Denial of Service (DoS)

These attacks aim to overload RFID systems and disrupt their function in order to prevent authorized access.


Side channel attacks

This involves analyzing the physical properties of the RFID system, such as power consumption or electromagnetic emissions, in order to derive confidential information.


Cryptanalytical attacks

These attacks aim to break the cryptographic mechanisms used to protect the data in RFID systems.


Physical attacks

These include methods such as physically destroying RFID tags or changing their internal structures in order to disrupt their function or obtain information.


Phone malware

A vulnerability was found in Android devices in 2019. Using NFC, it was possible to download software that is not offered in the Google Play Store. Normally, the smartphone warns in such a case. The download triggered by this vulnerability did not trigger these warnings, but the user still had to confirm the download. This vulnerability has now been closed.[2]


Physical shielding of the tag

To circumvent Electronic Article Surveillance (EAS), thieves use multi-layered aluminium pockets, creating a Faraday cage, to shield the tag from the reader.


Social Engineering

Social engineering is not a direct attack, but social engineering can be used to gain access to NFC or RFID devices, which makes it possible to clone them or steal information.


Tools

There are a lot of different tools to attack RFID-Systems. Well known tools are:

  1. Flipper Zero is a powerful and multi-functional tool specifically created for pentesting and device hacking purposes. This is a little gadget that has the ability to communicate with many wireless systems, such as RFID, NFC, and radio frequencies. Flipper Zero is very proficient in analysing and evaluating the security of RFID systems. It may be used for various activities like as duplicating RFID tags, intercepting communications, and investigating weaknesses in wireless protocols.[3]
  2. ChameleonMini is a specialised device designed to emulate and clone RFID tags, with a particular focus on contactless card technology. It is often used in security research to assess the resilience of RFID systems against cloning and spoofing attacks. The ChameleonMini is a versatile tool that can imitate several kinds of RFID tags and store different RFID identities. This makes it an effective device for researchers and security experts to evaluate and showcase the security risks associated with RFID technology.[4]
  3. The Keysy RFID Duplicator is a small and easy-to-use hardware device designed to replicate Mifare cards, which are widely used for access control, public transit, and payment systems. Users are able to replicate and retain numerous sets of RFID tag data, so gaining the ability to reproduce the same functionality as these cards. This tool is very valuable for assessing and showcasing weaknesses in access control systems that are based on Mifare technology, hence emphasising possible security hazards in RFID implementations of such systems.[5]
  4. The Proxmark3 RDV4 is a refined and condensed iteration of the Proxmark3. It was created specifically for the community of professionals that do penetration tests. The frequencies 125kHz and 13.56MHz are the defining characteristics. The device is equipped with several antennas and may be expanded using diverse modules.[6]

Security experts and researchers often use these tools to assess and scrutinise the security of RFID systems.

Security controls for RFID

This section addresses security measures that are relevant to the majority of implementations. It fails to consider the security aspects of RFID-enabled smart cards and payment systems. Furthermore, it omits any mention of security measures pertaining to conventional IT systems, such as network infrastructure, databases, and web servers, since they are already addressed by existing security prerequisites and standards. To ensure the security of the data collected by the RFID system, it is important to protect EPCIS servers that can be accessed over the Internet by trading partners. This can be done by implementing similar controls that are used for any other system accessible over the Internet, such as encrypting sensitive communications and implementing access control measures to prevent unauthorised access to data and systems. Various sources, including NIST's Computer Security Resource Centre (CSRC), provide guidelines on areas such as IT server, application, database, and network security.

References