SSR-Labs · Security White Paper

Closer to the Bits.

A field report on the real-world (in)security of RFID, NFC, MIFARE and automotive keyfob cryptography — and on verifying a break before you believe it.

Abstract

Nearly every access badge, car key, hotel lock and transit token in circulation still leans on cryptography that the academic community dismantled between 2005 and 2015. The ciphers are small, the keys are short, and the attacks are public. What is not common is the discipline to implement those attacks correctly and to prove each one before trusting its output. This paper surveys the broken transponder ciphers, states plainly which of them the SSR-Labs suite reproduces bit-for-bit against published test vectors, and reports measured crack speeds — including two in-house GPU kernels benchmarked on a single consumer graphics card. Where more speed is available but harder to verify, we say so, and we ship the verified version.

§ 1

The transponder threat surface

Contactless credentials split cleanly by frequency. Low frequency (125 kHz) is the world of vehicle immobilizers and legacy access fobs: Hitag2, Megamos Crypto, Texas Instruments DST, EM4100, HID Prox. High frequency (13.56 MHz) is the world of NFC — MIFARE Classic, Ultralight, DESFire, NTAG, iCLASS. The two bands demand different antennas and different tools, but they share one property that makes this paper possible: for a large installed base, the secret protecting the credential is computed by a cipher that no longer holds.

The consequences are not academic. A cloned immobilizer transponder starts a car. A recovered MIFARE Classic sector key opens a door, refills a stored-value purse, or forges a hotel master. A cleartext EM4100 badge is copied in seconds. The question a security team should ask is never "is it encrypted?" but "which cipher, and is that cipher broken?"

TechnologyBandTypical useCryptographic status
MIFARE Classic (Crypto-1)13.56 MHzAccess, transit, stored valueBroken (2008)
Hitag2 / ID46125 kHzCar immobilizer, RKEBroken (2012)
Megamos Crypto / ID48125 kHzVAG-era immobilizerBroken (2013/15)
TI DST40 / DST80134 kHzImmobilizer, payment fobBroken (2005 / 2020)
KeeLoqRF remoteRolling-code RKE / gatesBroken (2008)
HID iCLASS legacy13.56 MHzAccess controlBroken (2012)
Atmel SecureMemory / CryptoMemory13.56 MHzAuthenticated EEPROMBroken (2010)
EM4100 / HID Prox125 kHzBadgesNo secret (cleartext ID)
DESFire EV2/EV3, SEOS, MIFARE Plus SL313.56 MHzModern access / paymentAES — no practical break
§ 2

A tour of the broken ciphers

What follows is a working attacker's map, not a literature review. Each entry states what the cipher protects, how it fails, and — the part that matters for a tool you would actually deploy — whether SSR-Labs reproduces it against a known-answer test (a published input/output vector), or merely implements the specification where no such vector exists.

Crypto-1 (MIFARE Classic)

A 48-bit stream cipher with a filter generator over an LFSR. Nohl et al. reverse-engineered the silicon in 2008; Garcia et al. formalized the attacks. The nested, darkside, mfkey32 and hardnested techniques recover sector keys from sniffed authentications or a single known key. SSR-Labs ships its own in-house Crypto-1 engine (ssrcrypto.dll) covering mfkey32, nested, nested_multi, darkside, static-nested and the Fudan FM11RF08S static-nested case — with a live blind crack of a MIFARE S50 in roughly 42 seconds on CPU.

Hitag2 (ID46)

A 48-bit cipher guarding a huge population of vehicle immobilizers and remote entry systems. Verdult, Garcia and Balasch's "Gone in 360 Seconds" (2012) turned two sniffed authentications into a practical key recovery. SSR-Labs' Hitag2 core is verified bit-exact against the AdamLaurie/RFIDler reference vector D8A13560 (post-init keystream) and drives dictionary, weak-key, masked and GPU-accelerated recovery.

Megamos Crypto (ID48)

The 96-bit-key, 57-bit-state cipher behind VAG-group immobilizers of the 2005–2013 era — famous for the two-year injunction that delayed its publication. With the transponder's partial key material recovered from the tag, SSR-Labs' native solver returns the full 96-bit key candidates immediately.

Texas Instruments DST40 & DST80

DST40's 40-bit key fell to Bono et al. in 2005 (the Exxon SpeedPass / immobilizer break); DST80 (Wouters et al., 2020) shares the round function. SSR-Labs implements the DST40 cipher against the public vectors 5CA1BA and CD6504, and DST80 against four Apache-licensed vectors — then brute-forces the 40-bit space on CPU or GPU.

KeeLoq, iCLASS legacy, Atmel CryptoMemory

KeeLoq's NLFSR block cipher (verified here against vector E44F4CDF) underpins rolling-code remotes; SSR-Labs models the cipher and hop-decoding but deliberately ships no manufacturer keys. iCLASS legacy key diversification (hash0 over single-DES) is verified against nine Proxmark vectors plus a DES vector. The Atmel SecureMemory/CryptoMemory stream cipher is the one honest asterisk in the set — see §3.

§ 3

Methodology: prove the break, don't assume it

A cipher implementation that looks right and even round-trips can still be subtly wrong — a swapped tap, an off-by-one in the key schedule, a byte-order slip. Such a bug produces confident, useless output. SSR-Labs' answer is a single rule applied without exception: every shipped cipher is checked, bit-for-bit, against a published known-answer test (KAT), and a one-button self-test runs the whole set on start-up.

15/15crypto engines pass the built-in self-test
14verified bit-exact against public KATs
1spec-true, flagged (no public KAT exists)

The one exception is stated openly rather than hidden. The Atmel SecureMemory/CryptoMemory cipher has a fully published specification (Garcia et al., CCS 2010; Biryukov et al., 2011) but no public numeric test vector. SSR-Labs implements it faithfully and verifies what can be verified — the 109-/117-bit state geometry, the modular-addition and rotation primitives, determinism, and a behavioural invariant the paper itself derives (an output-correlation of exactly ¾). Bit-exactness we mark pending, because integrity means never labelling "spec-true" as "verified".

The SSR-Labs advantage · Oracle-gated cracking

A GPU — or any external tool — never earns our trust; the in-house reference cipher does. Every candidate key a kernel returns is re-checked against our own bit-exact core before it is reported as found. A wrong answer from a fast tool is caught, not shipped.

// Oracle gate — the kernel proposes, our verified core disposes.
foreach (Match m in Regex.Matches(gpuStdout, "[0-9A-Fa-f]{12}")) {
    ulong cand = Convert.ToUInt64(m.Value, 16);
    // re-derive the keystream with SSR-Labs' own Hitag2 cipher:
    if (auths.All(a => Keystream32(cand, uid, a.Nonce) == a.Ks))
        return cand;   // confirmed — safe to report
}

Excerpt — SSR-Labs suite, Ht2GpuBridge. In-house code.

§ 4

Benchmarks: how fast, honestly

Speed is where marketing usually detaches from truth, so here are numbers we measured — CPU figures per single thread, GPU figures on one NVIDIA GeForce RTX 5050 (entry-class Blackwell, OpenCL 3.0), each GPU kernel first verified on that same card against its KAT. The two GPU kernels are SSR-Labs' own OpenCL, built as zero-dependency hosts: no CUDA toolkit, no SDK, no registry entry — they run on a stock GeForce driver.

100K 1M 10M 100M 1B keys tested / second (log scale) DST40 · CPU/thread 0.2 M/s Hitag2 · CPU/thread 1.7 M/s DST40 · GPU (RTX 5050) 135 M/s Hitag2 · GPU (RTX 5050) 1.1 B/s
In-house OpenCL kernels (red) vs. single-thread CPU reference (grey). Both GPU kernels KAT-verified on the same card before benchmarking.
TargetThroughputFull keyspaceWith known upper bits
Hitag2 · GPU (own kernel)~1.1 B keys/s2⁴⁸ ≈ 3 days2⁴⁰ ≈ 16 min · 2³⁴ ≈ 15 s
Hitag2 · blind recovery2³⁵ G&Dseconds–minutes—
DST40 · GPU (own kernel)~135 M keys/s2⁴⁰ ≈ 2.3 hseconds
MIFARE Classic · live blind—~42 s (S50, CPU)instant w/ 1 known key
Megamos ID48 · solver—instant w/ tag partial—
Honest note · there is more speed on the table

These are not the ceiling. Full bit-slicing of the DST40 kernel, an in-house Hitag2 2³⁵ guess-and-determine in OpenCL, and a GPU port of the MIFARE hardnested attack would each push the numbers higher — plausibly by another order of magnitude in places. We have not shipped them, and we will not quote them as fact, because every one of those optimizations trades transparency for speed: the code gets harder to verify against a known answer, and a subtle error becomes easy to introduce and hard to catch. SSR-Labs' rule holds — a result is only as good as the test that proves it. The roadmap items are labelled as roadmap.

§ 5

What SSR-Labs has that others don't

§ 6

Defensive recommendations

The reason to measure a break precisely is to retire the thing that breaks. For asset owners and security teams:

Takeaways
  • Retire Crypto-1. Move MIFARE Classic access and stored value to DESFire EV2/EV3 (AES) or MIFARE Plus SL3. Do not treat a Classic sector key as a secret.
  • Retire the broken LF immobilizer ciphers. Hitag2, DST40 and Megamos Crypto should give way to AES variants (Hitag AES, DST80-AES, Megamos AES/ID88).
  • Treat EM4100 / HID Prox as identifiers, not credentials. They carry no secret and are copied in seconds; layer a real authenticator on top.
  • Access control: migrate iCLASS legacy to SEOS. Diversify keys per UID (AN10922, done correctly); never deploy a global key.
  • Rolling-code remotes: size counter windows sensibly and use fresh entropy; understand RollJam/RollBack/RollingPWN as your own exposure, not just an abstraction.
  • Where the tag supports it, enable authentication-attempt limits so an online brute force is not even an option.
§ 7

Scope & responsible use

The SSR-Labs suite is a diagnostic instrument for owners and authorized testers. It is built exclusively from public and open-source research; it contains no manufacturer or conditional-access keys, no leaked specifications, and no turnkey vehicle-theft or pay-TV tooling. Rolling-code and relay attacks are modelled at an awareness level so defenders understand their exposure — not packaged as one-click openers. Every capability in this paper is intended for lawful, authorized security assessment.

§ 8

References

  1. Nohl, Evans, Starbug, Plötz. Reverse-Engineering a Cryptographic RFID Tag. USENIX Security, 2008.
  2. Garcia, de Koning Gans, Muijrers, van Rossum, Verdult, Schreur, Jacobs. Dismantling MIFARE Classic. ESORICS, 2008.
  3. Verdult, Garcia, Balasch. Gone in 360 Seconds: Hijacking with Hitag2. USENIX Security, 2012.
  4. Verdult, Garcia, Ege. Dismantling Megamos Crypto: Wirelessly Lockpicking a Vehicle Immobilizer. USENIX Security, 2015 (written 2013).
  5. Bono, Green, Stubblefield, Juels, Rubin, Szydlo. Security Analysis of a Cryptographically-Enabled RFID Device (TI DST40). USENIX Security, 2005.
  6. Wouters, Van den Herrewegen, Garcia, Oswald, Gierlichs, Preneel. Dismantling DST80-based Immobiliser Systems. IACR TCHES, 2020.
  7. Garcia, van Rossum, Verdult, Schreur. Dismantling SecureMemory, CryptoMemory and CryptoRF. ACM CCS, 2010.
  8. Biryukov, Kizhvatov, Zhang. Cryptanalysis of the Atmel Cipher in SecureMemory, CryptoMemory and CryptoRF. ACNS, 2011 (IACR ePrint 2011/707).
  9. Meijer, Verdult. Ciphertext-only Cryptanalysis on Hardened MIFARE Classic Cards. ACM CCS, 2015.
  10. Indesteege, Keller, Dunkelman, Biham, Preneel. A Practical Attack on KeeLoq. EUROCRYPT, 2008.
  11. Garcia, de Koning Gans, Verdult, Meriac. Dismantling iCLASS and iCLASS Elite. ESORICS, 2012.