NXP Semiconductors MIFARE Classic Smartcard Multiple Security Weaknesses
BID:31853
Info
NXP Semiconductors MIFARE Classic Smartcard Multiple Security Weaknesses
| Bugtraq ID: | 31853 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 21 2008 12:00AM |
| Updated: | Oct 22 2008 03:16PM |
| Credit: | Flavio D. Garcia, Gerhard de Koning Gans, Ruben Muijrers, Peter van Rossum, Roel Verdult, Ronny Wichers Schreur, and Bart Jacobs of Radboud University Nijmegen |
| Vulnerable: |
NXP Semiconductors MiFARE Classic 0 |
| Not Vulnerable: | |
Discussion
NXP Semiconductors MIFARE Classic Smartcard Multiple Security Weaknesses
MIFARE Classic is prone to multiple security weaknesses:
1. A security weakness may allow attackers to recover the internal state of the linear feedback shift register.
2. A security weakness may allow attackers to recover the previous state of the linear feedback shift register.
3. A security weakness may allow attackers to invert the filter function and potentially gain access to the private key.
4. A security weakness may allow attackers to reduce the search space for tag nonces.
Exploiting these issues in combination may allow attackers to gain access to the smartcard's secret key. Successful exploits will allow attackers with physical access to an RFID reader to bypass certain physical security restrictions.
MIFARE Classic is prone to multiple security weaknesses:
1. A security weakness may allow attackers to recover the internal state of the linear feedback shift register.
2. A security weakness may allow attackers to recover the previous state of the linear feedback shift register.
3. A security weakness may allow attackers to invert the filter function and potentially gain access to the private key.
4. A security weakness may allow attackers to reduce the search space for tag nonces.
Exploiting these issues in combination may allow attackers to gain access to the smartcard's secret key. Successful exploits will allow attackers with physical access to an RFID reader to bypass certain physical security restrictions.
Exploit / POC
NXP Semiconductors MIFARE Classic Smartcard Multiple Security Weaknesses
Attackers would need physical access to the RFID reader.
The following exploit code is available:
Attackers would need physical access to the RFID reader.
The following exploit code is available:
Solution / Fix
NXP Semiconductors MIFARE Classic Smartcard Multiple Security Weaknesses
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
NXP Semiconductors MIFARE Classic Smartcard Multiple Security Weaknesses
References:
References:
- Vendor Homepage (NXP Semiconductors)
- [tool] crapto1 released ([email protected] )
- Dismantling MIFARE Classic (Flavio D. Garcia, Gerhard de Koning Gans, Ruben Muijrers)