Monday, 3 September 2012

NFC: To Secure or not to Secure?


NFC security



Much controversy subsists as to the security of
Near Field Communication transactions. While
defenders of NFC technology are convinced that
the very short range between the device and the
reader make it inviolable or argue that security is
not a big issue in NFC applications, others
believe that security risks will hamper the takeoff
of NFC services.


 

All depends on the type of NFC application

Of course, all depends on what you want to do with NFC and the mechanisms deployed to meet the security requirements of each application. Basically, since NFC enables users to set up communication between 2 devices, some use case scenarios such as peer-to-peer (P2P) transfer of data present little or no threat to the two parties involved. Other, tag reading services which give access to digital content and real time, location based interactivity services or mobile internet sites, open up the risk of spyware or malware attacks from un-controlled sources. Finally, the most sensitive NFC scenario is that of digital card emulation for contactless payment, access to buildings or travel tickets for example.

Determine the value of your NFC applications

Applications which provide information and which have no specific security requirements such as P2P and Smart Tag reading. However, this does not mean that there is no risk of misuse: users shall avoid exchanging P2P information with unknown people, as they could transfer malware or spyware to the phone. The same applies to smart tag reading: users should check if they trust the SmartTag issuer, as the link could lead them to unsafe/hacking pages and the subsequent risk of having unwanted items installed in their device.

 High value applications such as payment, banking or ticketing or retail offers, couponing and loyalty applications are the obvious target for malicious users and therefore carry high security requirements. To resolve security issues we need to distinguish between the insensitive part of the NFC application which will be installed on the mobile device, and the sensitive data part ( such as credentials or payment codes) which will be stored in a secure execution environment, referred to as the SE (secure element).

Integrating a Secure Element

The SE can be integrated in different form factors:
  • SIM Card (SIM/UICC)
  • NFC MicroSD card: special MicroSD including the SE
  • Embedded Secure Element (ESE): at manufacture stage

While mobile operators will most probably pick the SIM card as a secure element, other players like Google, banks and service providers are going for ESE or Micro SD. Of course there pros and cons for each of them but sicap believes that the SIM card is fundamentally compatible from both a security and a usability point of view. There is a SIM card in every GSM mobile phone, it is removable and easily exchangeable if new security requirements arise. And it leaves the SD slot free for photo, music and other applications.


Want to get informed as soon as a new article has been posted? Subscribe!

1 comment:

  1. "this does not mean that there is no risk of misuse: users shall avoid exchanging P2P information with unknown people, as they could transfer malware or spyware to the phone. The same applies to smart tag reading: users should check if they trust the SmartTag issuer, as the link could lead them to unsafe/hacking pages and the subsequent risk of having unwanted items installed in their device"
    Congratulations, you are one of the very few who understands/explains exactly the risk. Most writers just post spectacular headlines about hacking, to attract visitors.

    ReplyDelete