The Internet of Things (IoT) is a distributed system of physical objects that requires the seamless integration of hardware (e.g., sensors, actuators, electronics) and network communications in order to collect and exchange data. IoT smart objects need to be somehow identified to determine the origin of the data and to automatically detect the elements around us. One of the best positioned technologies to perform identification is RFID (Radio Frequency Identification), which in the last years has gained a lot of popularity in applications like access control, payment cards or logistics. Despite its popularity, RFID security has not been properly handled in numerous applications. To foster security in such applications, this article includes three main contributions. First, in order to establish the basics, a detailed review of the most common flaws found in RFID-based IoT systems is provided, including the latest attacks described in the literature. Second, a novel methodology that eases the detection and mitigation of such flaws is presented. Third, the latest RFID security tools are analyzed and the methodology proposed is applied through one of them (Proxmark 3) to validate it. Thus, the methodology is tested in different scenarios where tags are commonly used for identification. In such systems it was possible to clone transponders, extract information, and even emulate both tags and readers. Therefore, it is shown that the methodology proposed is useful for auditing security and reverse engineering RFID communications in IoT applications. It must be noted that, although this paper is aimed at fostering RFID communications security in IoT applications, the methodology can be applied to any RFID communications protocol.
翻译:物联网(IoT)是一个由物理对象组成的分布式系统,需要通过硬件(如传感器、执行器、电子设备)与网络通信的无缝集成来收集和交换数据。物联网智能对象需以某种方式被识别,以确定数据来源并自动检测我们周围的元素。在实现识别的技术中,射频识别(RFID)是最具优势的技术之一。近年来,RFID在门禁控制、支付卡、物流等应用中广受欢迎。尽管其普及度高,但在众多应用中RFID安全性并未得到妥善处理。为促进此类应用的安全性,本文包含三项主要贡献:首先,为奠定基础,详细综述了基于RFID的物联网系统中最常见的缺陷,包括文献中描述的最新攻击手段;其次,提出了一种便于检测和缓解此类缺陷的新方法;最后,分析了最新的RFID安全工具,并通过其中一种工具(Proxmark 3)应用所提方法进行验证。因此,该方法在标签常用于识别的不同场景中进行了测试。在这些系统中,我们实现了应答器的克隆、信息提取,甚至标签与读写器的仿真。研究表明,所提方法有助于在物联网应用中对RFID通信进行安全审计与逆向工程。需特别说明的是,虽然本文旨在提升物联网应用中RFID通信的安全性,但该方法可适用于任何RFID通信协议。