29.05.2015 • News

Nedap's AEOS maximises resistance to DESFire relay attacks

NFC-enabled credit cards have received much attention because of their vulnerability to relay attacks. Widely used NXP DESFire EV1 cards use the same technology, and are vulnerable...

NFC-enabled credit cards have received much attention because of their vulnerability to relay attacks. Widely used NXP DESFire EV1 cards use the same technology, and are vulnerable to relay attacks, which raised concern in the access control market. A relay attack fraudulently extends the distance between smart card and card reader enabling, for example, unauthorised access to buildings. Research carried out by the Dutch knowledge institute TNO has proved that Nedap's security platform AEOS maximises resistance to relay attacks.

It has been known for some time that so-called proximity communication - as described in the ISO/IEC 14443 protocol - is vulnerable to relay attacks. It only requires two smartphones with built-in NFC technology to extend the distance between card and reader without restrictions. Extending this communication distance, however, creates a delay. By applying much stricter delay times in all of its card readers than is prescribed by the ISO/IEC 14443 protocol, Nedap significantly reduces the chances of possible relay attacks.

As in 2009, when Nedap was the first manufacturer to respond to the possible security risks of the Mifare Classic chip, Nedap has moved quickly to give its clients the best protection. In response to the TNO research, Nedap has reduced the delay times of its card readers even further, without having to make concessions to user-friendliness. Because AEOS can provide card readers with new firmware remotely, clients can now get better protection against relay attacks at the press of a button.

Proximity check

To prevent the chance of relay attacks, NXP applies a check between card and reader in its Mifare Plus X technology to determine whether the card is actually in the proximity of the reader. The successor of the much-used DESFire EV1-chip, the DESFire EV2-chip, is also expected to have this built-in proximity check. Until this card is launched, however, it is the responsibility of users to map out the security risks together with their suppliers. Manufacturers therefore face the task of developing solutions to minimise the risks.

 

Intersec

Highlights of Intersec Dubai 2026
Intersec Dubai

Highlights of Intersec Dubai 2026

Best products, most interesting booths. Read our follow-up report. And how physical security, cyber-security and AI-driven intelligence are converging into integrated security architectures.

Fire Protection

Safety Solutions for the Westminster Palace

Safety Solutions for the Westminster Palace

The Bosch subsidiary Protec has equipped the entire grounds of Westminster Palace with fire and voice alarm technology.

most read

Photo

Meet Martin Reguero: Optex's new Key Account Manager in Madrid

Martin Reguero has recently joined Optex as Key Account Manager, based in Madrid. With over 30 years' experience in the security industry, Martin brings a wealth of expertise in intrusion systems, access control, CCTV and fire detection. His career combines practical knowledge of installations with extensive experience in commercial and customer service roles.