Séminaire de Cryptographie

Accueil     Présentation     Archives

Timo Kasper


How to break Remote Keyless Entry Systems.

KeeLoq remote keyless entry systems are widely used for access control purposes such as garage openers or car door systems. The talk will present the first successful differential power analysis attacks on numerous commercially available products employing KeeLoq code hopping. They allow for efficiently revealing both the secret key of a remote transmitter and the manufacturer key stored in a receiver. As a result, a remote control can be cloned from only ten power traces, allowing for a practical key recovery in few minutes. After extracting the manufacturer key once, with similar techniques, it is possible to recover the secret key of a remote control and replicate it from a distance, just by eavesdropping on at most two messages. This key-cloning without physical access to the device has devastating real-world implications, as the technically challenging part can be outsourced to specialists. During the talk, the attack will be practically performed. Finally, it will be shown how to take over control of a KeeLoq access control system, i.e., lock out a legitimate user while the attacker may still open the door.