Skip to main content

Millions of cars at risk due to flaw in keyless entry systems, say researchers

Researchers at the University of Birmingham in the UK have found that millions of cars could be vulnerable to theft, due to a flaw in keyless entry systems in many models. The findings, presented at the 25th USENIX Security Symposium in Austin, Texas, highlight two case studies that outline the ease at which criminals could gain access to numerous vehicles with relatively simple and inexpensive methods. Both attacks use a cheap, easily available piece of radio hardware to intercept signals from a key
August 15, 2016 Read time: 3 mins
Researchers at the University of Birmingham in the UK have found that millions of cars could be vulnerable to theft, due to a flaw in keyless entry systems in many models.

The findings, presented at the 25th USENIX Security Symposium in Austin, Texas, highlight two case studies that outline the ease at which criminals could gain access to numerous vehicles with relatively simple and inexpensive methods.

Both attacks use a cheap, easily available piece of radio hardware to intercept signals from a key fob and then employ those signals to clone the key.

Though most automotive immobiliser systems have been shown to be insecure in the last few years, the security of remote keyless entry systems to lock and unlock a car based on rolling codes has received less attention.

The team, Flavio D. Garcia, David Oswald and Pierre Pavlidès, from the School of Computer Science at the University of Birmingham and Timo Kasper of Kasper & Oswald, found that the security of the keyless entry systems of most VW Group vehicles manufactured between 1995 and today relies on a few global master keys.  

By recovering the cryptographic algorithms and keys from electronic control units, a thief would be able to clone a VW Group remote control and gain unauthorised access to a wirelessly unlock practically every vehicle the Volkswagen group has sold for the last two decades, including makes like Audi and Škoda, by eavesdropping a single signal sent by the original remote.

A second case study outlines an attack that could affect millions more vehicles, including Alfa Romeo, Citroen, Fiat, Ford, Mitsubishi, Nissan, Opel/Vauxhall, Renault, and Peugeot.

The researchers devised a correlation-based attack on Hitag2, which allows recovery of the cryptographic key and thus cloning of the remote control with four to eight rolling codes and a few minutes of computation on a laptop.

Oswald explained, “You only need to eavesdrop once. From that point on you can make a clone of the original remote control that locks and unlocks a vehicle as many times as you want. Manufacturers really need to take heed and review their security systems.”

Garcia added, “It’s a bit worrying to see security techniques from the 1990s used in new vehicles. If we want to have secure, autonomous, interconnected vehicles, that has to change. Unfortunately the fix won’t be easy, as there is quite a slow software development cycle, new designs will be quite a long time in the making.”

The researchers suggest that car owners with affected vehicles avoid leaving any valuables in their car, and consider giving up on wireless key fobs altogether and open and lock their car doors the ‘old-fashioned’, mechanical way.

Related Content

  • April 29, 2016
    VW and Shell try to block EU push for electric cars
    VW and Shell have united to try to block Europe’s push for electric cars and more efficient cars, saying biofuels should be at heart of efforts to green the industry instead. The EU is planning two new fuel efficiency targets for 2025 and 2030 to help meet promises made at the Paris climate summit last December. But executives from the two organisations launched a study on Wednesday night proposing greater use of biofuels, CO2 car labelling, and the EU’s emissions trading system (ETS) instead.
  • March 16, 2016
    Revenue growth of 30 per cent forecast for connected car market in 2016
    According to research company Statista’s Digital Market Outlook (DMO), 2016 will see approximately 11 million connected cars in America, with almost 32 million intelligent cars on America’s streets by 2020. Worldwide the number of connected cars is forecast to rise to 160 million intelligent vehicles. Statista claims the main impact of the enormous growth of the market comes from the rapid development of new features and possibilities. The biggest segment however, according to the DMO, is not infotainmen
  • June 28, 2016
    PSA Group and TomTom collaborate to offer fleet management services
    Carmaker PSA Group and TomTom Telematics are to make the TomTom Webfleet fleet management solution available for all connected Peugeot, Citroën, and DS fleet vehicles. As of next quarter, the service will become accessible in France, Spain, Belgium and the Netherlands. Webfleet helps fleet managers to save fuel as well as localise vehicle positions and improve car maintenance planning. Within the collaboration between PSA Group and TomTom Telematics, the platform will use the data sent by the manufactur
  • March 9, 2016
    Intersection monitoring from video using 3D reconstruction
    Researchers Yuting Yang, Camillo Taylor and Daniel Lee have developed a system to turn surveillance cameras into traffic counters. Traffic information can be collected from existing inexpensive roadside cameras but extracting it often entails manual work or costly commercial software. Against this background the Delaware Valley Regional Planning Commission (DVRPC) was looking for an efficient and user-friendly solution to extract traffic information from videos captured from road intersections.