Publications-NSC Projects

Article View/Open

Publication Export

Google ScholarTM

NCCU Library

Citation Infomation

Related Publications in TAIR

題名 一個對於RFID資訊系統遞接式攻擊(relay attack)複合解決方案之研究
A Study That Investigates a Hybrid Solution against Rfid Relay Attack
作者 杜雨儒
貢獻者 資管系
關鍵詞 無線射頻識別系統; 遞接式攻擊(relay attack); 複合式解決方案
RFID system; relay attack; hybrid solution
日期 2021-03
上傳時間 10-Jun-2026 11:54:18 (UTC+8)
摘要 在目前世界各地,利用RFID系統(讀取器和標籤)以自動化提供識別數據,品項數據等等,是一個確立的趨勢,然而 relay attack 卻始終是在RFID數據管控安全上,一個嚴重的威脅。尤其當2018年5月,歐盟通用數據保護法(GDPR)正式生效,對於處理RFID relay attack 問題的需求和壓力更是大幅加劇。儘管RFID relay attack可以有非常多的變異,但其本質上單單只是在RFID讀取器和標籤間,偷偷中繼轉傳 (pass on) 遞接數據。但也就是因如此簡單即可執行,使得在處理RFID relay attack問題上,份外棘手,因其幾乎完全不同於一般的駭入行為。最近BBC新聞報導中即指出,relay car theft 似已成了一種新興犯罪,並發現數種高單價轎車都已受害,且犯罪過程只需以秒計。這些竊車賊既沒有盜取車主的鑰匙,也無破解任何密碼或設備,簡單只是將RFID標籤的外溢數據,例如: PKES車鑰的身份識別數據,加以中轉,就可輕易打開車鎖。另一方面眾所周知的是,幾乎所有現存relay attack解決方法都有其相對限制。透過系統性的審查整理後,本研究計畫發現此些方法主要可分為兩類。舉例而言,文獻中幾乎所有RFID distance-bounding數據認證協定(protocol)皆是依賴計時器功能,其他RFID non-distance-bounding協定則仰賴感應環境條件的功能,以達阻遏的效果。鑒於其各自有其長短之處,因此本研究計畫主要目標在於發展一複合式解決方法,汲取現存兩種協定之特性,以利防範relay attack的威脅。綜上所述,此研究計畫主要有三方面貢獻。其一,無論是著眼於RFID系統在自動化辨識上已確立的使用趨勢,或是基於RFID數據管控安全上,日益升高的要求,此計畫所產生之研究成果有其即時性和必要性。其二,此研究是少數領先的研究,其聚焦於統整分析現存諸多解決方案,並據以提出一可行的複合式方案,其成果對於跨學科的RFID相關研究領域,像是RFID資訊系統/決策支援系統,RFID數據信息安全,RFID自動辨識服務提供和治理,都將非常有價值。其三,此研究計畫中所提出之RFID數據認證協定,是以輕量化方式設計發展,無需使用太多計算資源,此珍貴特點將使其可適用於多數市面上被動式(無電池/無電源)RFID系統。
Worldwide, it is a trend of using RFID system (RFID reader and tag) as the automated provider of identity data, item-level data, and so forth. However, relay attack remains one notorious threat to RFID data security in cyberspace. As GDPR (General Data Protection Regulation) takes effective in May 2018, the need and pressure for addressing RFID relay attack largely escalate. While it may have considerable variants, RFID relay attack essentially is done by simply passing on data between RFID reader and tag. This implementation simplicity makes it extremely hard to deal with relay attack, since mounting this attack does not entail any specific and professional knowledge for breaking into any security system, encryption algorithm, etc. Simply put, all of what relay attacker needs to do is to relay data only, such that relay attack is often referred as the “zero-knowledge” attack. For example, one recent BBC news report in 2018 indicates that relay car theft increasingly becomes a new breed of crime. A number of high-valued cars across brands, such as Audi, BMW and Jaguar, are already found stolen by the same theft technique and it takes merely dozen of seconds to implement. Those car thieves neither steal the owners’ car key fobs nor break any car security devices. Rather, they simply capture the spilled-over signals that contain identity data from car owners’ RFID key fobs, such as PKES (Passive Keyless Entry and Start) car keys, and pass on the data to unlocking the cars. On the other hand, it is well recognized that almost of all the extant relay attack solutions have their limitations respectively. Thus, after a systematic review of the existing solutions, this study classifies them into two distinctive types: the timer-based and sensor-based. For example, the timer-based solution may refer to the RFID authentication protocols that are reliant on round-trip-time for handling relay attack (i.e., distance-bounding protocols). The sensor-based solution may refer to the protocols that are dependent on ambient condition for tackling relay attack (i.e., non-distance-bounding protocols). In view of their relative strengths and limitations, this study develops a hybrid RFID authentication protocol for fusing both merits of the timer-based and sensor-based relay attack countermeasures.Overall, the contribution of this study is three-fold. First, this is one timely and necessary research work, considering the trend of using RFID for automatic identification and the increased requirement of securing data communication in cyberspace (e.g., GDPR). Moreover, this is one first RFID research work that critically analyzes several possible alternatives and proposes a feasible hybrid solution for thwarting relay attack, which makes this study very valuable to the interdisciplinary research areas that pertains to RFID-based information systems/decision support systems, cyberspace data security, automated identity service and governance, etc. Lastly, the proposed RFID protocol in this study is lightweight, which suggests that the computing resource constraint of this protocol is low. It is thus compatible with most passive RFID system (with battery-free RFID tags) in the market and this feature is rare in practice.
關聯 科技部, MOST108-2410-H004-200, 108.08-109.07
資料類型 report
dc.contributor 資管系
dc.creator (作者) 杜雨儒
dc.date (日期) 2021-03
dc.date.accessioned 10-Jun-2026 11:54:18 (UTC+8)-
dc.date.available 10-Jun-2026 11:54:18 (UTC+8)-
dc.date.issued (上傳時間) 10-Jun-2026 11:54:18 (UTC+8)-
dc.identifier.uri (URI) https://ah.lib.nccu.edu.tw/item?item_id=182873-
dc.description.abstract (摘要) 在目前世界各地,利用RFID系統(讀取器和標籤)以自動化提供識別數據,品項數據等等,是一個確立的趨勢,然而 relay attack 卻始終是在RFID數據管控安全上,一個嚴重的威脅。尤其當2018年5月,歐盟通用數據保護法(GDPR)正式生效,對於處理RFID relay attack 問題的需求和壓力更是大幅加劇。儘管RFID relay attack可以有非常多的變異,但其本質上單單只是在RFID讀取器和標籤間,偷偷中繼轉傳 (pass on) 遞接數據。但也就是因如此簡單即可執行,使得在處理RFID relay attack問題上,份外棘手,因其幾乎完全不同於一般的駭入行為。最近BBC新聞報導中即指出,relay car theft 似已成了一種新興犯罪,並發現數種高單價轎車都已受害,且犯罪過程只需以秒計。這些竊車賊既沒有盜取車主的鑰匙,也無破解任何密碼或設備,簡單只是將RFID標籤的外溢數據,例如: PKES車鑰的身份識別數據,加以中轉,就可輕易打開車鎖。另一方面眾所周知的是,幾乎所有現存relay attack解決方法都有其相對限制。透過系統性的審查整理後,本研究計畫發現此些方法主要可分為兩類。舉例而言,文獻中幾乎所有RFID distance-bounding數據認證協定(protocol)皆是依賴計時器功能,其他RFID non-distance-bounding協定則仰賴感應環境條件的功能,以達阻遏的效果。鑒於其各自有其長短之處,因此本研究計畫主要目標在於發展一複合式解決方法,汲取現存兩種協定之特性,以利防範relay attack的威脅。綜上所述,此研究計畫主要有三方面貢獻。其一,無論是著眼於RFID系統在自動化辨識上已確立的使用趨勢,或是基於RFID數據管控安全上,日益升高的要求,此計畫所產生之研究成果有其即時性和必要性。其二,此研究是少數領先的研究,其聚焦於統整分析現存諸多解決方案,並據以提出一可行的複合式方案,其成果對於跨學科的RFID相關研究領域,像是RFID資訊系統/決策支援系統,RFID數據信息安全,RFID自動辨識服務提供和治理,都將非常有價值。其三,此研究計畫中所提出之RFID數據認證協定,是以輕量化方式設計發展,無需使用太多計算資源,此珍貴特點將使其可適用於多數市面上被動式(無電池/無電源)RFID系統。
dc.description.abstract (摘要) Worldwide, it is a trend of using RFID system (RFID reader and tag) as the automated provider of identity data, item-level data, and so forth. However, relay attack remains one notorious threat to RFID data security in cyberspace. As GDPR (General Data Protection Regulation) takes effective in May 2018, the need and pressure for addressing RFID relay attack largely escalate. While it may have considerable variants, RFID relay attack essentially is done by simply passing on data between RFID reader and tag. This implementation simplicity makes it extremely hard to deal with relay attack, since mounting this attack does not entail any specific and professional knowledge for breaking into any security system, encryption algorithm, etc. Simply put, all of what relay attacker needs to do is to relay data only, such that relay attack is often referred as the “zero-knowledge” attack. For example, one recent BBC news report in 2018 indicates that relay car theft increasingly becomes a new breed of crime. A number of high-valued cars across brands, such as Audi, BMW and Jaguar, are already found stolen by the same theft technique and it takes merely dozen of seconds to implement. Those car thieves neither steal the owners’ car key fobs nor break any car security devices. Rather, they simply capture the spilled-over signals that contain identity data from car owners’ RFID key fobs, such as PKES (Passive Keyless Entry and Start) car keys, and pass on the data to unlocking the cars. On the other hand, it is well recognized that almost of all the extant relay attack solutions have their limitations respectively. Thus, after a systematic review of the existing solutions, this study classifies them into two distinctive types: the timer-based and sensor-based. For example, the timer-based solution may refer to the RFID authentication protocols that are reliant on round-trip-time for handling relay attack (i.e., distance-bounding protocols). The sensor-based solution may refer to the protocols that are dependent on ambient condition for tackling relay attack (i.e., non-distance-bounding protocols). In view of their relative strengths and limitations, this study develops a hybrid RFID authentication protocol for fusing both merits of the timer-based and sensor-based relay attack countermeasures.Overall, the contribution of this study is three-fold. First, this is one timely and necessary research work, considering the trend of using RFID for automatic identification and the increased requirement of securing data communication in cyberspace (e.g., GDPR). Moreover, this is one first RFID research work that critically analyzes several possible alternatives and proposes a feasible hybrid solution for thwarting relay attack, which makes this study very valuable to the interdisciplinary research areas that pertains to RFID-based information systems/decision support systems, cyberspace data security, automated identity service and governance, etc. Lastly, the proposed RFID protocol in this study is lightweight, which suggests that the computing resource constraint of this protocol is low. It is thus compatible with most passive RFID system (with battery-free RFID tags) in the market and this feature is rare in practice.
dc.format.extent 116 bytes-
dc.format.mimetype text/html-
dc.relation (關聯) 科技部, MOST108-2410-H004-200, 108.08-109.07
dc.subject (關鍵詞) 無線射頻識別系統; 遞接式攻擊(relay attack); 複合式解決方案
dc.subject (關鍵詞) RFID system; relay attack; hybrid solution
dc.title (題名) 一個對於RFID資訊系統遞接式攻擊(relay attack)複合解決方案之研究
dc.title (題名) A Study That Investigates a Hybrid Solution against Rfid Relay Attack
dc.type (資料類型) report