KeeLoq security systems hacked

Researchers from Ruhr University Bochum, Germany have managed to hack remote keyless entry systems based on the KeeLoq RFID technology, one of the most popular security systems. All car and building access control systems that rely on the KeeLoq cipher have been proved to be vulnerable.

̶0;The security hole allows illegitimate parties to access buildings and cars after remote eavesdropping from a distance of up to 100 metres̶1; says Prof. Christof Paar. His Communication Security Group in the Electrical Engineering and Information Sciences Department has developed the break as part of their research in embedded security.

Prof. Paar̵7;s team found that car keys (or building keys) can be cloned from a distance of several 100 meters in the most devastating attack. ̶0;Eavesdropping on as little as two messages enables illegitimate parties to duplicate your key and to open your garage or unlock your car̶1;, says Prof. Paar.

With another malicious attack, a garage door or a car door can be remotely manipulated so that the legitimate keys will not work. As a consequence, access to the car or the building is not possible any more.

A KeeLoq system consists of an active Radio Frequency Identification (RFID) transponders (e.g., embedded in a car key) and a receiver (e.g., embedded in the car door). Both the receiver and transponder use KeeLoq as encryption method for securing the over-the-air communication.

The attack by the Bochum team allows recovering the secret cryptographic keys embedded in both the receiver and the responder. The attack is based on measuring the electric power consumption of the receiver. Applying what is called side-channel analysis methods to the power traces, the researchers were able to extract the manufacturer key from the receivers. The attack ̵1; which combines side-channel cryptanalysis with specific properties of the KeeLoq algorithm ̵1; can be applied to all known variants in which KeeLoq is used in real world systems.

The practicality of the attack has been confirmed by attacking actual systems which are using KeeLoq. KeeLoq has been used for access control since the mid-1990s. By some estimates, it is the most popular of such systems in Europe and the US.

Besides the frequent use of KeeLoq for garage door openers and other building access applications, it is also known that several automotive manufacturers like Toyota/Lexus base their anti-theft protection on assumed secure devices featuring KeeLoq.

Image: Access control systems, such as car doors, that rely on the KeeLoq cipher have been proved to be vulnerable

Recent articles

Info Message

Our sites use cookies to support some functionality, and to collect anonymous user data.

Learn more about IET cookies and how to control them

Close