Gone in 360 Seconds: Hijacking with Hitag2

نویسندگان

  • Roel Verdult
  • Flavio D. Garcia
  • Josep Balasch
چکیده

An electronic vehicle immobilizer is an anti-theft device which prevents the engine of the vehicle from starting unless the corresponding transponder is present. Such a transponder is a passive RFID tag which is embedded in the car key and wirelessly authenticates to the vehicle. It prevents a perpetrator from hot-wiring the vehicle or starting the car by forcing the mechanical lock. Having such an immobilizer is required by law in several countries. Hitag2, introduced in 1996, is currently the most widely used transponder in the car immobilizer industry. It is used by at least 34 car makes and fitted in more than 200 different car models. Hitag2 uses a proprietary stream cipher with 48-bit keys for authentication and confidentiality. This article reveals several weaknesses in the design of the cipher and presents three practical attacks that recover the secret key using only wireless communication. The most serious attack recovers the secret key from a car in less than six minutes using ordinary hardware. This attack allows an adversary to bypass the cryptographic authentication, leaving only the mechanical key as safeguard. This is even more sensitive on vehicles where the physical key has been replaced by a keyless entry system based on Hitag2. During our experiments we managed to recover the secret key and start the engine of many vehicles from various makes using our transponder emulating device. These experiments also revealed several implementation weaknesses in the immobilizer units.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Improving the Payoff from 360-Degree Feedback

further and linked the process to performance appraisal and succession planning, This article describes our research findings on the 360 feedback process. We have discovered six critical factors, or best practices, to help leaders in organizations get the most from their investment in the process. Additionally, we have found that organizations that derive the most benefit from the 360 feedback ...

متن کامل

Evaluating Potential of Electromagnetic Microwaves on Destruction Acanthamoeba Cysts

Background: Acanthamoeba is a free-living and opportunistic amoeba that the potential of this parasite to convert to a cyst, making its treatment difficult. In this study, we investigated the effect of microwave radiation on Acanthamoeba cysts in vitro. Materials and Methods: Acanthamoeba cysts were reproduced in the culture medium. We divided 16 test tubes containing cysts into two groups. Th...

متن کامل

Verapamil versus placebo in relieving stable angina pectoris.

Verapamil and placebo were compared in patients with stable, effort-induced angina. Single-blind dose titration (240, 360 and 480 mg/day) preceded a double-blind crossover. Among the 18 patients who completed graded exercise stress tests with reproducible pretreatment effort-limiting angina, exercise duration increased from 348 +/- 127 seconds (SD) before treatment to 494 +/- 182 seconds after ...

متن کامل

Percutaneous CT-guided cryoablation of the dorsal penile nerve for treatment of symptomatic premature ejaculation.

PURPOSE To evaluate expansion of image-guided interventional cryoablation techniques usually employed for pain management to address the feasibility, safety, and efficacy of treatment for a urologic condition with otherwise limited treatment options, premature ejaculation (PE). MATERIALS AND METHODS Prospective institutional review board approval was obtained, and 24 subjects with PE were enr...

متن کامل

Microhardness Evaluation of a Direct/Indirect Hybrid Composite Resin at Complementary Activation in Light or Heat

This investigation aims at determining the microhardness value of the hybrid direct/indirect composite resins submitted to conventional light curing and post-cured using two different methods, a light source from a laboratory light curing unit and a conventional oven heating, and the obtained results were compare to an indirect composite resin. A hybrid direct/indirect composite resin (Filtek P...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2012