How Android HCE Creates New Attack Surfaces for MIFARE DESFire
Mifare DESFire keycards are some of the most difficult keycards to clone. As such, they are used in access control, transit, closed loop payments, and many other sectors. Acquiring keys for DESFire cards has been borderline impossible thanks to its robust physical and digital security architecture. However, in recent years, technologies like Android HCE have enabled DESFire emulation on smartphones, allowing for easier distribution and management while integrating almost seamlessly with existing infrastructure.
This technology is what we will be exploiting. To get the card onto your phone, an app like Google Wallet or Samsung Pay needs to request it from a remote service. This provisioning process can easily be intercepted and decoded to reveal both the card data and keys.
VC Card
Before we begin, let’s go over the big difference between an emulated DESFire and a regular one. Android HCE requires something called a DFnameto call the...
Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE