USENIX Security2016Top-tier venue
Lock It and Still Lose It - on the (In)Security of Automotive Remote Keyless Entry Systems
Flavio D. Garcia, David F. Oswald, Timo Kasper, Pierre Pavlidès
Abstract
While most automotive immobilizer systems have been shown to be insecure in the last few years, the security of remote keyless entry systems (to lock and unlock a car) based on rolling codes has received less attention. In this paper, we close this gap and present vulnerabilities in keyless entry schemes used by major manufacturers. In our first case study, we show that the security of the keyless entry systems of most VW Group vehicles manufactured between 1995 and today relies on a few, global master keys. We show that by recovering the cryptographic algorithms and keys from electronic control units, an adversary is able to clone a VW Group remote control and gain unauthorized access to a vehicle by eavesdropping a single signal sent by the original remote. Secondly, we describe the Hitag2 rolling code scheme (used in vehicles made by Alfa Romeo, Chevrolet, Peugeot, Lancia, Opel, Renault, and Ford among others) in full detail. We present a novel correlation-based attack on Hitag2, which allows recovery of the cryptographic key and thus cloning of the remote control with four to eight rolling codes and a few minutes of computation on a laptop. Our findings affect millions of vehicles worldwide and could explain unsolved insurance cases of theft from allegedly locked vehicles.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d61d1083-d13d-4acf-9c63-8bbaf5788180Cited by top-tier papers12
- Losing the Car Keys: Wireless PHY-Layer Insecurity in EV ChargingRichard Baker, Ivan MartinovicUSENIX Security 2019 · 67 citations
- Modelling and Analysis of a Hierarchy of Distance Bounding AttacksTom Chothia, Joeri de Ruiter, Ben SmythUSENIX Security 2018 · 25 citations
- Revisiting Automotive Attack Surfaces: a Practitioners' PerspectivePengfei Jing, Zhiqiang Cai, Yingjie Cao, Le Yu et al.S&P 2024 · 16 citations
- MetaEmu: An Architecture Agnostic Rehosting Framework for Automotive FirmwareZitai Chen, Sam L. Thomas, Flavio D. GarciaCCS 2022 · 9 citations
- From Virtual Touch to Tesla Command: Unlocking Unauthenticated Control Chains From Smart Glasses for Vehicle TakeoverXingli Zhang, Yazhou Tu, Yan Long, Liqun Shan et al.S&P 2024 · 6 citations
Related papers
- Hold the Door! Fingerprinting Your Car Key to Prevent Keyless Entry Car TheftKyungho Joo, Wonsuk Choi, Dong Hoon LeeNDSS 2020
- BLE Theft Auto: Evaluating the Security of Aftermarket BLE-based Automotive Remote Control SystemsJerry Yu, Yibo Wei, Sumanth Rao, Mohak Vaswani et al.USENIX Security 2026
- Fingerprinting Electronic Control Units for Vehicle Intrusion DetectionKyong-Tak Cho, Kang G. ShinUSENIX Security 2016 · 524 citations
- Cloud-Native Carjacking: Fleet-wide Compromise via Telematics Authorization FailuresYangyang Liu, Zhengjie Du, Xiaofang Wang, Yang Yin et al.USENIX Security 2026
- Evading Voltage-Based Intrusion Detection on Automotive CANRohit Bhatia, Vireshwar Kumar, Khaled Serag, Z. Berkay Celik et al.NDSS 2021
