3 ms·
What sort of security implementations were you thinking of? There are companies out there aggressively working towards "uncloneable" cards and such. Secure ele
by kul 15y ago
What sort of security implementations were you thinking of? There are companies out there aggressively working towards "uncloneable" cards and such.
Secure elements for payments I think are pretty secure, more secure than credit cards at least.
Edit: here's one company that claims to it: http://www.verayo.com/products/unclonable-rfid http://www.verayo.com/products/unclonable-rfid
- drivebyacct2 15y agoI have come up with three different ideas: - Ultralight tags (fun because there are cheap wristbands out there that look fairly normal and have these embedded). You could use some sort of HMAC to encrypt a message that is based on the unique ID of the Ultralight tag. The reader could verify that the data on the tag is the encrypted message corresponding to that tag's ID. This is broken if anyone decides to clone a tag down to the serial ID. This would require custom tag fabrication or a misbehaving supplier. - Ultralight C tags: 3DES encryption [skipping details] you could have better prevention of cloning the tag. Unfortunately, 3DES encryption is symmetric and if anyone can access the reader, they can remove the key and again clone a tag. (This is how HID Class RFID cards work except they don't use 3DES and there are at least 3 ways of easily retrieving the master key) - SmartCard: Actual PKI with assymetric encryption so that someone can provide a challenge and the SmartCard can provide the proper response. Again, sadly, contactless cards and they're expensive. Other than that, I'm out of ideas. I'm a tinkerer and a student. The thing you've linked to looks like some sort of PKI in that there is a challenge/response scenario going on. All of this is information I've gleaned from Wikipedia over the past weekend and I would love to be corrected if I am wrong, even if it needs to take place somewhere other than this thread.