Skip to main content

Millions of cars at risk due to flaw in keyless entry systems, say researchers

Researchers at the University of Birmingham in the UK have found that millions of cars could be vulnerable to theft, due to a flaw in keyless entry systems in many models. The findings, presented at the 25th USENIX Security Symposium in Austin, Texas, highlight two case studies that outline the ease at which criminals could gain access to numerous vehicles with relatively simple and inexpensive methods. Both attacks use a cheap, easily available piece of radio hardware to intercept signals from a key
August 15, 2016 Read time: 3 mins
Researchers at the University of Birmingham in the UK have found that millions of cars could be vulnerable to theft, due to a flaw in keyless entry systems in many models.

The findings, presented at the 25th USENIX Security Symposium in Austin, Texas, highlight two case studies that outline the ease at which criminals could gain access to numerous vehicles with relatively simple and inexpensive methods.

Both attacks use a cheap, easily available piece of radio hardware to intercept signals from a key fob and then employ those signals to clone the key.

Though most automotive immobiliser systems have been shown to be insecure in the last few years, the security of remote keyless entry systems to lock and unlock a car based on rolling codes has received less attention.

The team, Flavio D. Garcia, David Oswald and Pierre Pavlidès, from the School of Computer Science at the University of Birmingham and Timo Kasper of Kasper & Oswald, found that the security of the keyless entry systems of most VW Group vehicles manufactured between 1995 and today relies on a few global master keys.  

By recovering the cryptographic algorithms and keys from electronic control units, a thief would be able to clone a VW Group remote control and gain unauthorised access to a wirelessly unlock practically every vehicle the Volkswagen group has sold for the last two decades, including makes like Audi and Škoda, by eavesdropping a single signal sent by the original remote.

A second case study outlines an attack that could affect millions more vehicles, including Alfa Romeo, Citroen, Fiat, Ford, Mitsubishi, Nissan, Opel/Vauxhall, Renault, and Peugeot.

The researchers devised a correlation-based attack on Hitag2, which allows recovery of the cryptographic key and thus cloning of the remote control with four to eight rolling codes and a few minutes of computation on a laptop.

Oswald explained, “You only need to eavesdrop once. From that point on you can make a clone of the original remote control that locks and unlocks a vehicle as many times as you want. Manufacturers really need to take heed and review their security systems.”

Garcia added, “It’s a bit worrying to see security techniques from the 1990s used in new vehicles. If we want to have secure, autonomous, interconnected vehicles, that has to change. Unfortunately the fix won’t be easy, as there is quite a slow software development cycle, new designs will be quite a long time in the making.”

The researchers suggest that car owners with affected vehicles avoid leaving any valuables in their car, and consider giving up on wireless key fobs altogether and open and lock their car doors the ‘old-fashioned’, mechanical way.

Related Content

  • January 6, 2017
    VW faces first legal test case over emissions in Germany
    German consumer rights champion myRight filed the first legal test case against Volkswagen (VW) in Germany on Tuesday, raising pressure on the carmaker to compensate customers in Europe over the emissions scandal, according to Reuters. VW has pledged billions to compensate US owners of its diesel-powered cars, but has so far rejected any compensation for the 8.5 million affected vehicles in Europe where different legal rules weaken the chances of affected customers winning a pay-out. Instead, VW is in
  • November 2, 2017
    Moneybarn: 1,800% increase in UK electric car registrations over five year period
    Nearly 10,000 electric cars are now registered in the UK with Japanese and German manufacturers dominating most popular brands in the UK, according to a five-year analysis on the development of the Electric vehicle industry by Moneybarn. These findings have been revealed following the government’s plan to ban the sale of all petrol and diesel vehicles from 2040.
  • June 13, 2013
    Global V2V penetration into new vehicles to rise by 2027
    A new report from ABI research concludes that global vehicle to vehicle (V2V) penetration into new vehicles will increase from just over 10 per cent in 2018 to 70 per cent in 2027, with the EU, US, and Japan as key regions adopting V2V in the mid-term. “V2X market and regulatory dynamics vary greatly from region to region. While the US will decide whether or not to mandate V2X by the end of 2013 with implementation not expected before 2018, in Europe the Car 2 Car Communication Consortium (C2C-CC) has issue
  • July 4, 2016
    Rolls-Royce publishes vision of the future of autonomous shipping
    A white paper published by the Rolls-Royce led Advanced Autonomous Waterborne Applications Initiative (AAWA) outlines the project’s vision of how remote and autonomous shipping will become a reality. Published to coincide with its presentations at the Autonomous Ship Technology Symposium 2016 in Amsterdam, the AAWA whitepaper explores the research carried out to date on the business case for autonomous applications, the safety and security implications of designing and operating remotely operated ships,