Surveying the security of access systems in Uppsala, Sweden
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F68407700%3A21240%2F23%3A00366805" target="_blank" >RIV/68407700:21240/23:00366805 - isvavai.cz</a>
Result on the web
<a href="https://doi.org/10.1109/MECO58584.2023.10154971" target="_blank" >https://doi.org/10.1109/MECO58584.2023.10154971</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1109/MECO58584.2023.10154971" target="_blank" >10.1109/MECO58584.2023.10154971</a>
Alternative languages
Result language
angličtina
Original language name
Surveying the security of access systems in Uppsala, Sweden
Original language description
Today, many people use several access systems on a daily basis without paying attention to the fact that many of the technologies in use are obsolete and insecure. For example, there are published attacks against all generations of MIFARE Classic cards and cloning a MIFARE Ultralight card is trivial. In this paper, we look into the security of several access systems in a student town Uppsala in Sweden. We evaluate the security of the cards or tags used for access as well as some of the security of the systems themselves. We present a detailed report on the configurations, including any vulnerabilities, while also presenting attacks exploiting these vulnerabilities, as well as real-life examples of how these attacks can be dangerous to the end user. We compare these systems to a well-designed system in the same city and suggest fixes for all vulnerabilities we found. When presenting the potential fixes, we pay attention to the ease and cost of the fixes.
Czech name
—
Czech description
—
Classification
Type
D - Article in proceedings
CEP classification
—
OECD FORD branch
20206 - Computer hardware and architecture
Result continuities
Project
—
Continuities
S - Specificky vyzkum na vysokych skolach
Others
Publication year
2023
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Article name in the collection
Proceedings of 2023 12th Mediterranean Conference on Embedded Computing (MECO)
ISBN
979-8-3503-2291-0
ISSN
2637-9511
e-ISSN
2637-9511
Number of pages
5
Pages from-to
—
Publisher name
IEEE
Place of publication
Piscataway
Event location
Budva
Event date
Jun 6, 2023
Type of event by nationality
WRD - Celosvětová akce
UT code for WoS article
—