United Business Media EE Times


Search

HOMEMARKET INTELLIGENCE UNITFORUMSDESIGNNEW PRODUCTSCAREERSBLOGSCONTACTEVENTSSIGN UP!RSSMost Popular contentTrusted Sources

 

Cellphone could crack RFID tags, says cryptographer
Print this article Email this article Reprints RSS Digital Edition

EE Times


SAN JOSE — A well known cryptographer has applied power analysis techniques to crack passwords for the most popular brand of RFID tags.

Adi Shamir, professor of computer science at the Weizmann Institute, reported his work in a high-profile panel discussion at the RSA Conference here. Separately, Ron Rivest, who co-developed the RSA algorithms with Shamir, used the stage of the annual panel to call for an industry effort to create a next-generation hashing algorithm to replace today’s SHA-1.

In recent weeks, Shamir used a directional antenna and digital oscilloscope to monitor power use by RFID tags while they were being read. Patterns in power use could be analyzed to determine when the tag received correct and incorrect password bits, he said.

Cryptographer
Adi Shamir

"The reflected signals contain a lot of information," Shamir said. "We can see the point where the chip is unhappy if a wrong bit is sent and consumes more power from the environment…to write a note to RAM that it has received a bad bit and to ignore the rest of the string," he added.

"I haven’t tested all RFID tags, but we did test the biggest brand and it is totally unprotected," Shamir said. Using this approach, "a cellphone has all the ingredients you need to conduct an attack and compromise all the RFID tags in the vicinity," he added.

Shamir said the pressure to get tags down to five cents each has forced designers to eliminate any security features, a shortcoming that needs to be addressed in next-generation products.

Separately, cryptographers discussed the weaknesses in the fundamental SHA-1 hashing algorithm that were announced at the group’s panel in 2005. "That was a real wake up call for cryptographers," said Rivest, who is also professor of electrical engineering and computer science at MIT.

"I would like to see a process like the industry conducted for the AES algorithm to work on a new hash function that could be delivered by 2010," Rivest said. "We are skating too close to the edge with the hash functions we use now," he added.

The National Institute of Standards and Technology ran the program that resulted in AES, but complained last year it lacked the resources in the near term to develop a similar program for hash functions.

"My guess is they will get pushed into doing this again," said Rivest in an interview after the panel. "A four-year time frame is probably fine for a technology bake off. There’s no reason to panic," he added.

"If it was brought up by this panel, it will probably spark a fire and the NSA or someone will get something going," said Sheueling Chang, a distinguished engineer in cryptography at Sun Microsystems who attended the panel.






  Free Subscription to EE Times
First Name Last Name
Company Name Title
Email address
  Click here for your Free Subscription to EETimes Europe
 
CAREER CENTER
Looking for a new job?
SEARCH JOBS
SPONSOR

RECENT JOB POSTINGS
CAREER NEWS
DoD Recognizes University Scientists For Basic Research
Annual awards to university faculty to conduct next-generation research projects were announced this week by the Defense Department.

For more great jobs, career related news, features and services, please visit EETimes' Career Center.



All White Papers »   

  Around Silicon Strategies

10 emerging technologies to watch: EE Times has compiled a list of emerging technologies that we think will be worth watching out for in 2010. Biofeedback or thought-control of electronics are among the contenders. More...

Hot applications in 2010: We've compiled a list of 10 technology applications you should watch for in 2010, ranging from e-book readers to 3-D TVs. We examine the features that make these apps so compelling as well unresolved issues. More...

Top 25 predictions for semis in 2010: 2010 is just beginning to unfold in the electronics industry. Looking into our crystal ball, we have released our own chip forecasts--and other predictions--for 2010. More...

Seven things to fix in 2010: The editors of EE Times came up with their own informal list of things we hope engineers fix in 2010, spanning everything from nano-lithography to space travel. What do you want to see get done this year? More...

'09 moves that are shaping the future: This was a brutal year, but the industry gets a nod for showing grace under fire. Here's our Top 10 guide to the coming year, illustrating what to expect in 2010. More...

10 CEOs out in 2009: It's been a tough year for the global electronics industry and CEOs. We survey the dismissal of 10 industry CEOs during the first three quarters of 2009 and what's ahead for the rest of the year. More...

Notable women in microelectronics: There is no better time than a global economic recession to examine the keys to successful corporate governance. So, EE Times has compiled an international list that celebrates women who are business and technology leaders in semis. More...

EE Times updates Silicon 60: Seventeen companies have been added to the lastest version of our Silicon 60 list of emerging startups. Forty-three companies survived as emerging companies that are still worth watching. More...

 
Education and
Learning


Learn Now:












Home | About | Editorial Calendar | Feedback | Subscriptions | Newsletter | Media Kit | Contact | Reprints|  RSS|   Digital|  Mobile
Network Websites
International
Network Features




All materials on this site Copyright © 2010 TechInsights, a Division of United Business Media LLC All rights reserved.
Privacy Statement | Terms of Service | About