NFCEraser: A Security Threat of NFC Message Modification Caused by Quartz Crystal Oscillator

Jianshuo Liu, Hong Li, Mengjie Sun, Haining Wang, Hui Wen, Zhi Li

IEEE Symposium on Security and Privacy 2024 · Day 2 · Continental Ballroom 4

Overview

In the rapidly expanding landscape of Near Field Communication (NFC) technology, where convenience often takes precedence, the security implications of wireless message exchange remain a critical area of research. This talk, "NFCEraser: A Security Threat of NFC Message Modification Caused by Quartz Crystal Oscillator," presented by Jianshuo Liu and his team, unveils a novel and concerning vulnerability in NFC passive communication systems. The research demonstrates a sophisticated method for an attacker to intentionally modify the content of messages transmitted between an NFC initiator (reader) and a peer device (tag or card) by precisely manipulating the quartz crystal oscillator circuit within the initiator through electromagnetic interference (EMI).

Watch on YouTube

Visual summary for NFCEraser: A Security Threat of NFC Message Modification Caused by Quartz Crystal Oscillator by Jianshuo Liu, Hong Li, Mengjie Sun, Haining Wang, Hui Wen, Zhi Li
Visual summary for NFCEraser: A Security Threat of NFC Message Modification Caused by Quartz Crystal Oscillator by Jianshuo Liu, Hong Li, Mengjie Sun, Haining Wang, Hui Wen, Zhi Li

Key moments

  1. 0:00 Introduction to NFC and existing attack limitations
  2. 2:00 Introducing NFC Eraser vulnerability and research goals
  3. 2:40 Overview of the NFC Eraser attack scheme
  4. 3:30 Key challenges: signal injection and content control
  5. 5:30 Core discovery: Injecting signals into crystal oscillator
  6. 8:10 Controlling content: detecting communication mode and flipping bits
  7. 9:00 Experimental results: high success rate in flipping card numbers

NFCEraser: A Security Threat of NFC Message Modification Caused by Quartz Crystal Oscillator

Speakers: Jianshuo Liu, Student, University of Chinese Academy of Sciences; Hong Li; Mengjie Sun; Haining Wang, Professor, Virginia Tech; Hui Wen; Zhi Li

Conference: IEEE S&P

YouTube: https://www.youtube.com/watch?v=QvM7e8q38p0

Overview

In the rapidly expanding landscape of Near Field Communication (NFC) technology, where convenience often takes precedence, the security implications of wireless message exchange remain a critical area of research. This talk, "NFCEraser: A Security Threat of NFC Message Modification Caused by Quartz Crystal Oscillator," presented by Jianshuo Liu and his team, unveils a novel and concerning vulnerability in NFC passive communication systems. The research demonstrates a sophisticated method for an attacker to intentionally modify the content of messages transmitted between an NFC initiator (reader) and a peer device (tag or card) by precisely manipulating the quartz crystal oscillator circuit within the initiator through electromagnetic interference (EMI).

The significance of NFCEraser lies in its ability to overcome the limitations of previous NFC attack vectors. While prior work focused on eavesdropping on transmitted data or launching denial-of-service (DoS) attacks, these methods largely failed to achieve targeted modification of specific data payloads. NFCEraser, however, provides a mechanism for an attacker to selectively flip bits within an NFC message, thereby corrupting or altering critical information such as card numbers or access credentials. This represents a substantial escalation in the potential threat posed to NFC applications, from digital payments and smart locks to file sharing and smart tags, necessitating a re-evaluation of current NFC security paradigms and inspiring the development of more robust countermeasures.

Background

▶ Watch: Introduction to NFC and existing attack limitations (0:00)

NFC technology has become an indispensable part of modern daily life, facilitating seamless short-range wireless communication for a myriad of applications. Its market size has seen continuous growth, underscoring its widespread adoption in areas like contactless payments, access control systems, and data exchange between devices. Despite its convenience, the inherent wireless nature of NFC communication introduces various security risks that researchers have actively explored.

Previous studies have primarily identified two categories of attacks against NFC systems. The first, eavesdropping or magnetic field probing, involves an attacker placing a magnetic field probe near an NFC initiator to sense changes in the amplitude of modulated magnetic signals. By analyzing these fluctuations, an attacker can infer the content of the transmitted messages. While this allows for passive information gathering, it does not enable active manipulation of the data. The second category comprises denial-of-service (DoS) attacks, where an attacker directly injects strong magnetic field signals into the NFC communication channel. The objective here is to disrupt the communication, making the NFC initiator unable to read any legitimate content from the peer device. This effectively blocks transactions but, similar to eavesdropping, does not permit the attacker to tamper with specific data being transmitted.

The critical gap in existing NFC attack methodologies was the inability to perform targeted data modification. Attackers could listen in or shut down communication, but they lacked the precision to alter specific bits or bytes of a message as it traversed the air interface. This limitation meant that while privacy and availability could be compromised, the integrity of the data itself, once transmitted, was largely considered secure from external manipulation during transit. The NFCEraser research directly addresses this gap, posing a new challenge to the integrity of NFC communications by demonstrating a practical method to achieve intentional message modification through a novel electromagnetic side-channel attack.

Key Findings

▶ Watch: Overview of the NFC Eraser attack scheme (2:40)

The NFCEraser research uncovers a critical vulnerability in NFC passive communication systems, demonstrating that specific electromagnetic interference (EMI) can be used to intentionally modify received NFC messages. The primary finding is the identification of the quartz crystal oscillator within the NFC initiator as a susceptible target for such manipulation. By injecting carefully crafted radio frequency (RF) signals into this circuit, attackers can alter the amplitude of the carrier signal, leading to bit flips in the data received by the NFC reader.

Specifically, the researchers discovered that transmitting out-of-band frequency signals to the crystal oscillator can cause the operating point of its amplifying components to drift. This drift, in turn, reduces the gain applied to the legitimate in-band 13.56 MHz carrier signal, thereby decreasing its amplitude. Conversely, other specific signal injections can increase the carrier amplitude. These amplitude changes, when precisely timed, can cause the NFC initiator to misinterpret the load-modulated responses from the peer device, leading to the successful modification of transmitted data.

The practical efficacy of NFCEraser was validated through extensive experiments using six different off-the-shelf commercial NFC communication modules. The attack achieved impressive success rates ranging from 63% to 89% when attempting to flip all bytes of card numbers of varying lengths. This high success rate underscores the practical feasibility and significant threat posed by this attack vector.

Furthermore, the study identified several key factors influencing the attack's performance:

  1. Attack Distance: The distance between the attacker's antenna and the NFC initiator's crystal oscillator directly impacts the energy required for a successful attack. Greater distances necessitate higher energy attack signals.
  2. Probing Distance: The distance at which the attacker's magnetic field probe can reliably detect changes in the magnetic field amplitude is crucial for timing the attack. The researchers observed that beyond 4 centimeters, it became nearly impossible to accurately detect amplitude changes, limiting the physical range for precise attack synchronization.
  3. Noise Power: Environmental noise significantly affects the attack's success rate. When the ambient noise power reached approximately 40 watts in the 1-500 MHz range, the success rate dropped below 50%, indicating that a sufficiently noisy environment can hinder the attack.

These findings highlight a previously unaddressed vulnerability, providing a new attack vector that can tamper with specific data payloads, unlike prior eavesdropping or DoS attacks. The research offers critical insights into the physical layer security of NFC and provides a foundation for developing robust defensive strategies.

Technical Deep Dive

▶ Watch: Key challenges: signal injection and content control (3:30)

The NFCEraser attack hinges on a sophisticated understanding of the NFC passive communication system and the precise manipulation of its core components. An NFC passive communication system fundamentally consists of two parts: an NFC initiator (typically a reader or smartphone) and an NFC peer device (such as a tag, card, or another smartphone in tag mode). These two devices communicate wirelessly via magnetic coils operating at a carrier frequency of 13.56 MHz. The initiator generates the carrier signal, which inductively powers the passive peer device and establishes the communication channel.

The communication process unfolds in three key stages:

  1. Field Generation: The initiator generates the 13.56 MHz RF field to establish power and communication.
  2. Command Transmission: The initiator sends data reading or writing commands to the peer device by modulating the 13.56 MHz carrier.
  3. Response by Load Modulation: Upon receiving a command, the peer device responds by load modulation. This involves altering its own impedance, which in turn reflects changes back to the initiator's magnetic field, effectively modulating the 13.56 MHz carrier signal received by the initiator. These subtle amplitude changes encode the peer device's response data (bits 1 or 0).

The crucial component targeted by NFCEraser is the quartz crystal oscillator circuit within the NFC initiator. This circuit is responsible for generating the stable 13.56 MHz carrier signal. It typically comprises a quartz crystal, a pair of electrodes, capacitors, and an inverting amplifier. The amplifier has a limited and fixed total gain, designed to operate optimally around the 13.56 MHz frequency.

The core technical breakthrough of NFCEraser is the discovery that injecting specific out-of-band frequency signals into this crystal oscillator circuit can alter the amplitude of the channel carrier signal. When both out-of-band and in-band frequency components are fed into an amplifier, the out-of-band signals can cause the amplifier's operating point to drift. This drift reduces the effective gain available for the intended in-band 13.56 MHz signal. Consequently, the amplitude of the carrier signal generated by the crystal oscillator and subsequently transmitted by the NFC coil decreases.

The researchers experimentally validated this mechanism. Injecting a 230 MHz out-of-band signal to the crystal oscillator electrodes resulted in a 15% decrease in the magnetic field signal strength outputted from the NFC coils. Conversely, injecting a DSBC (Double-Sideband Suppressed Carrier) modulated signal with a carrier frequency of 230 MHz and a base frequency of 6.78 MHz caused a 6% increase in the carrier amplitude without introducing extra frequency components in the frequency domain. These experiments unequivocally demonstrated the feasibility of manipulating the carrier amplitude via targeted EMI.

To successfully launch the NFCEraser attack, two key challenges had to be overcome:

  1. Signal Injection: The intuitive approach of directly injecting magnetic signals into the communication channel (Option A) proved unstable, causing erratic energy reception by the peer device. The successful approach (Option B) involved injecting specific RF signals directly into the crystal oscillator circuit to subtly alter the carrier's amplitude.
  2. Transmission Content Control: To achieve targeted bit flipping, the attacker needs precise control over the timing and characteristics of the injected malicious signals. This involves two steps:
  • Detecting NFC Communication Mode: The attacker first uses a magnetic probe to detect the NFC communication mode (NFC-A or NFC-B) based on the unique signal modulation depths and waveforms. This detection is crucial when the initiator sends a command frame to the peer device.
  • Generating Attack Signal Sequence: Once the peer device begins to respond with its response frame, the attacker immediately generates and transmits a sequence of attack signals. These signals are configured according to the specific bit values the attacker intends to flip. By precisely timing the injection of signals that cause an amplitude increase or decrease, the attacker can force the NFC initiator to misinterpret a "1" as a "0" or vice-versa during load modulation decoding.

The NFC communication frame formats and modulation waveforms vary between NFC-A and NFC-B modes, requiring the attacker to adapt their attack signal sequence accordingly. By understanding these nuances, the NFCEraser attack achieves its remarkable precision in modifying specific data payloads transmitted over the NFC channel.

Demo / Proof of Concept

▶ Watch: Controlling content: detecting communication mode and flipping bits (8:10)

The practical viability of the NFCEraser attack was rigorously demonstrated through a series of experiments. The researchers utilized six different off-the-shelf commercial NFC communication modules to ensure the findings were not specific to a single hardware implementation but rather indicative of a broader vulnerability.

The primary objective of the demonstration was to showcase the attack's ability to achieve targeted data modification. Specifically, the team aimed to flip all bytes of card numbers of varying lengths, simulating a realistic scenario where sensitive data like payment card information could be compromised. Each attack scenario was repeated 100 times to gather statistically significant results on the success rates.

The results were compelling: NFCEraser achieved success rates ranging between 63% and 89% across the different byte lengths and NFC modules tested. This wide range of success rates suggests that while the attack is highly effective, its performance can vary depending on the specific hardware, environmental factors, and the length of the data being targeted. However, even the lowest success rate of 63% is significant enough to pose a serious security risk, demonstrating that the attack is not merely a theoretical concept but a practical threat capable of consistently corrupting data.

Beyond the core success rate, the demo also evaluated the impact of various environmental and operational factors on the attack's efficacy:

  • Attack Distance: The experiments showed a direct correlation between the distance from the attacker's antenna to the NFC initiator's crystal oscillator and the energy required for a successful attack. This highlights the need for proximity but also indicates that with sufficient power, the attack range can be extended.
  • Probing Distance: The ability to accurately detect NFC communication for timing purposes was found to be sensitive to the probing distance. Magnetic field probes struggled to detect amplitude changes when placed more than 4 centimeters away from the NFC coil, suggesting a practical constraint on the attacker's positioning for precise synchronization.
  • Noise Power: The presence of ambient electromagnetic noise was shown to negatively impact the attack's success. In environments with average noise distribution (1-500 MHz) and approximately 40 watts of noise power, the attack success rate dropped below 50%. This indicates that noisy environments can offer a degree of natural protection against NFCEraser.

The successful demonstration across multiple commercial devices, coupled with the detailed analysis of influencing factors, firmly establishes NFCEraser as a potent and validated security threat to NFC systems.

Defensive Implications

▶ Watch: Experimental results: high success rate in flipping card numbers (9:00)

The NFCEraser attack unveils a critical, previously underexplored vulnerability in the physical layer security of NFC systems, demanding immediate attention from product designers, developers, and security practitioners. The ability to actively modify specific data payloads during transmission, rather than just eavesdrop or deny service, has profound implications for the integrity of NFC-based transactions and data exchanges.

Defenders must now consider the quartz crystal oscillator within NFC initiators as a potential attack surface. Traditional shielding measures might not adequately protect against precisely tuned out-of-band RF signals that exploit the non-linear behavior of amplifier circuits. Therefore, a multi-faceted defense strategy is essential:

  1. Enhanced Electromagnetic Shielding: NFC initiator designs should incorporate more robust and comprehensive electromagnetic shielding, particularly around sensitive components like the quartz crystal oscillator and its associated amplifier circuits. This shielding should be effective not only against in-band 13.56 MHz signals but also against a broad spectrum of out-of-band frequencies (e.g., 230 MHz as demonstrated in the talk) that could induce the amplifier drift.
  2. Improved Filtering: Implementing advanced filtering mechanisms at the input stage of the crystal oscillator circuit can help mitigate the threat. These filters should be designed to aggressively reject out-of-band frequency components that could perturb the amplifier's operating point, ensuring that only the intended signals reach the sensitive circuitry.
  3. Hardware-Level Integrity Checks: While software-level error detection codes (EDC) and cyclic redundancy checks (CRC) are standard, the NFCEraser attack occurs at a very low level, potentially before these checks are applied or in a way that might bypass simpler EDCs. Hardware-level integrity checks, possibly involving redundant signal processing or real-time monitoring of amplifier stability, could be explored to detect anomalous carrier amplitude fluctuations that are not part of legitimate load modulation.
  4. Robust Error Correction Codes (ECC): While not a direct prevention, stronger error correction codes could help mitigate the impact of successful bit flips. ECCs can detect and correct a certain number of errors, potentially restoring the original message even if a few bits are flipped by an NFCEraser attack. However, very targeted or extensive bit flips might overwhelm standard ECCs.
  5. Physical Security of NFC Readers: For high-security applications like payment terminals or access control systems, the physical security of NFC readers becomes even more paramount. Preventing an attacker from placing an antenna in close proximity to the reader's internal components is a fundamental defense. This might involve tamper-resistant enclosures or environmental monitoring for unusual RF activity.
  6. Review of Amplifier Design: Product designers should review the specifications and resilience of amplifiers used in crystal oscillator circuits. Selecting amplifiers with greater immunity to out-of-band interference and less susceptibility to operating point drift under external RF fields could enhance robustness.
  7. Dynamic Frequency Hopping/Spread Spectrum (if applicable): While challenging for passive NFC, exploring techniques like dynamic frequency hopping or spread spectrum communication could make it significantly harder for an attacker to precisely target the carrier frequency with their malicious signals, as the carrier might not be static.

The NFCEraser attack underscores the need for a holistic security approach that extends beyond cryptographic protocols and software vulnerabilities to encompass the physical layer and electromagnetic properties of wireless communication. Ignoring such vulnerabilities could lead to severe consequences for the integrity of data in critical NFC applications.

Key Takeaways

  • Novel Attack Vector: NFCEraser introduces a new and potent attack vector against NFC passive communication systems, enabling targeted modification of transmitted messages.
  • Targeted Data Manipulation: Unlike previous NFC attacks (eavesdropping, DoS), NFCEraser can actively flip specific bits within an NFC message, compromising data integrity.
  • Crystal Oscillator Vulnerability: The attack exploits the quartz crystal oscillator circuit in the NFC initiator by injecting out-of-band RF signals, causing amplifier drift and altering the carrier signal's amplitude.
  • High Success Rates: Experiments demonstrated success rates between 63% and 89% in flipping bytes of card numbers on off-the-shelf commercial NFC modules.
  • Practical Feasibility: The attack requires careful timing, achieved by probing the NFC magnetic field, but is practically feasible with readily available equipment.
  • Defensive Imperatives: Product designers must implement enhanced electromagnetic shielding, improved filtering, robust error correction, and consider the physical security of NFC readers to mitigate this threat.

About the Speaker(s)

The primary presenter for this work was Jianshuo Liu, a student at the University of Chinese Academy of Sciences. He presented the team's research on NFCEraser, detailing the novel security threat and its underlying mechanisms. The research was a joint effort, including contributions from Professor Haining Wang of Virginia Tech, indicating a collaboration between academic institutions to investigate critical vulnerabilities in widely used technologies like NFC. The talk also credited Hong Li, Mengjie Sun, Hui Wen, and Zhi Li as co-authors of this significant study.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This research unveils NFCEraser, a critical and novel attack vector that enables targeted bit manipulation within NFC messages by precisely interfering with the initiator's quartz crystal oscillator. Validated with high success rates on commercial devices, this work fundamentally shifts the threat model for NFC, moving beyond mere eavesdropping or denial-of-service to active data integrity compromise.

Heather Calloway (CISO) — STRONG ACCEPT

This research identifies a critical and practical physical layer vulnerability in NFC, demonstrating how targeted electromagnetic interference can actively modify sensitive data like card numbers. It provides clear, actionable defensive strategies, forcing a re-evaluation of hardware security and risk ownership for organizations reliant on NFC systems.

→ Top-rated talks at IEEE Symposium on Security and Privacy 2024

All talks from IEEE Symposium on Security and Privacy 2024