Skip to main content

Millions of cars at risk due to flaw in keyless entry systems, say researchers

Researchers at the University of Birmingham in the UK have found that millions of cars could be vulnerable to theft, due to a flaw in keyless entry systems in many models. The findings, presented at the 25th USENIX Security Symposium in Austin, Texas, highlight two case studies that outline the ease at which criminals could gain access to numerous vehicles with relatively simple and inexpensive methods. Both attacks use a cheap, easily available piece of radio hardware to intercept signals from a key
August 15, 2016 Read time: 3 mins
Researchers at the University of Birmingham in the UK have found that millions of cars could be vulnerable to theft, due to a flaw in keyless entry systems in many models.

The findings, presented at the 25th USENIX Security Symposium in Austin, Texas, highlight two case studies that outline the ease at which criminals could gain access to numerous vehicles with relatively simple and inexpensive methods.

Both attacks use a cheap, easily available piece of radio hardware to intercept signals from a key fob and then employ those signals to clone the key.

Though most automotive immobiliser systems have been shown to be insecure in the last few years, the security of remote keyless entry systems to lock and unlock a car based on rolling codes has received less attention.

The team, Flavio D. Garcia, David Oswald and Pierre Pavlidès, from the School of Computer Science at the University of Birmingham and Timo Kasper of Kasper & Oswald, found that the security of the keyless entry systems of most VW Group vehicles manufactured between 1995 and today relies on a few global master keys.  

By recovering the cryptographic algorithms and keys from electronic control units, a thief would be able to clone a VW Group remote control and gain unauthorised access to a wirelessly unlock practically every vehicle the Volkswagen group has sold for the last two decades, including makes like Audi and Škoda, by eavesdropping a single signal sent by the original remote.

A second case study outlines an attack that could affect millions more vehicles, including Alfa Romeo, Citroen, Fiat, Ford, Mitsubishi, Nissan, Opel/Vauxhall, Renault, and Peugeot.

The researchers devised a correlation-based attack on Hitag2, which allows recovery of the cryptographic key and thus cloning of the remote control with four to eight rolling codes and a few minutes of computation on a laptop.

Oswald explained, “You only need to eavesdrop once. From that point on you can make a clone of the original remote control that locks and unlocks a vehicle as many times as you want. Manufacturers really need to take heed and review their security systems.”

Garcia added, “It’s a bit worrying to see security techniques from the 1990s used in new vehicles. If we want to have secure, autonomous, interconnected vehicles, that has to change. Unfortunately the fix won’t be easy, as there is quite a slow software development cycle, new designs will be quite a long time in the making.”

The researchers suggest that car owners with affected vehicles avoid leaving any valuables in their car, and consider giving up on wireless key fobs altogether and open and lock their car doors the ‘old-fashioned’, mechanical way.

Related Content

  • September 24, 2015
    Volkswagen emissions – ‘a missing global standard is the issue’ say UK organisations
    The UK’s Transport Research Laboratory (TRL) and research organisation Frost and Sullivan have both commented on the Volkswagen diesel emissions scandal, which has resulted in the resignation of CEO Martin Winterkorn. The world's biggest carmaker by sales has admitted to US regulators that it programmed its cars to detect when they were being tested and altered the running of their diesel engines to conceal their true emissions. Winterkorn said, “I am shocked by the events of the past few days. Above
  • May 1, 2014
    Traffic control systems ‘vulnerable to hacking’
    Devices used by traffic control systems are vulnerable to being hacked, according to computer security specialist IOActive. Hackers could gain complete control of these devices and cause traffic issues for the cities in the US, UK, France, Australia, China and beyond.
  • July 28, 2015
    Nokia’s Here Maps sold to BMW, Daimler and Volkswagen
    After months of negotiation, Nokia sells the HERE Maps division to the German consortium, BMW, Daimler and Volkswagen for US$2.71 billion, according to the BMW blog. The3 news has yet to be confirmed by Here or the other auto makers. The deal would see HERE Maps turn into an open platform, which all car manufacturers can use for navigation and mapping inside vehicles. The three German car makers plan to offer the platform to Fiat Chrysler, Renault, Peugeot, Ford, Toyota and General Motors, allowing them
  • February 28, 2013
    Driverless vehicles just around the corner?
    umors that self-driving taxis are about to hit the streets of Las Vegas have turned out to be untrue… but the age of the driverless vehicle is only just around the corner, as Pete Goldin finds out. From Herbie the Love Bug to Knight Rider to the cast of the Pixar film Cars, the autono­mous auto has long been a beloved icon in the entertainment industry. But how close is the fiction to fact? The general public might be surprised to find out just how soon autonomous vehicles could be driving on our roadways.