The Bussard-Bagga and other distance-bounding protocols under attacks
Paper i proceeding, 2013

The communication between an honest prover and an honest verifier can be intercepted by a malicious man-in-the-middle (MiM), without the legitimate interlocutors noticing the intrusion. The attacker can simply relay messages from one party to another, eventually impersonating the prover to the verifier and possibly gaining the privileges of the former. This sort of simple relay attacks are prevalent in wireless communications (e.g.; RFID-based protocols) and can affect several infrastructures from contactless payments to remote car-locking systems and access-control verification in high-security areas. As the RFID/NFC technology prevails, a practical and increasingly popular countermeasure to these attacks is given by distance-bounding protocols. Yet, the security of these protocols is still not mature. Importantly, the implications of the return channel (i.e.; knowing whether the protocol finished successfully or not) in the security of some distance-bounding protocols have not been fully assessed. In this paper, we demonstrate this by a series of theoretical and practical attacks. We first show that the Bussard-Bagga protocol DBPK-Log does not fulfill its goal: it offers no protection against distance fraud and terrorist fraud. Then, we show how to mount several concrete MiM attacks against several follow-up variants, including the protocol by Reid et al. © 2013 Springer-Verlag Berlin Heidelberg.

Författare

A. Bay

Ecole Polytechnique Federale de Lausanne (EPFL)

I. Boureanu

Ecole Polytechnique Federale de Lausanne (EPFL)

Aikaterini Mitrokotsa

Ecole Polytechnique Federale de Lausanne (EPFL)

I. Spulber

Ecole Polytechnique Federale de Lausanne (EPFL)

S. Vaudenay

Ecole Polytechnique Federale de Lausanne (EPFL)

Proceedings of the 8th International Conference on Information Security and Cryptology (Inscrypt 2012)


9783642385186 (ISBN)

Styrkeområden

Informations- och kommunikationsteknik

Ämneskategorier (SSIF 2011)

Data- och informationsvetenskap

DOI

10.1007/978-3-642-38519-3_23

Mer information

Senast uppdaterat

2026-04-27