Power Analysis of RFID Tags
This is great work by Yossi Oren and Adi Shamir:
Abstract (Summary)
We show the first power analysis attack on passive RFID tags. Compared to standard power analysis attacks, this attack is unique in that it requires no physical contact with the device under attack. While the specific attack described here requires the attacker to actually transmit data to the tag under attack, the power analysis part itself requires only a receive antenna. This means that a variant of this attack can be devised such that the attacker is completely passive while it is acquiring the data, making the attack very hard to detect. As a proof of concept, we describe a password extraction attack on Class 1 Generation 1 EPC tags operating in the UHF frequency range. The attack presented below lets an adversary discover the kill password of such a tag and, then, disable it. The attack can be readily adapted to finding the access and kill passwords of Gen 2 tags. The main significance of our attack is in its implications any cryptographic functionality built into tags needs to be designed to be resistant to power analysis, and achieving this resistance is an undertaking which has an effect both on the price and on the read range of tags.
My guess of the industry’s response: downplay the results and pretend it’s not a problem.
Davi Ottenheimer • March 17, 2006 1:37 PM
You’re right. Since the RSA conference, when Adi brought this up on the Cryptographer’s Panel, I really haven’t seen much discussion about it…
http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1166550,00.html
“Shamir, professor at the Weizmann Institute of Science and the “S” in RSA, told a packed auditorium during the get-together of crypto hall-of-famers about how he and a student applied side-channel attacks against RFID tags. […] “Everyone expects RFID tags to be huge; they’re everywhere,” Shamir said. “They’re going to protect our identities in our passwords. They’re going to protect items in stores. The fact is, the first generation is very weak.””