Skip to the main content

Original scientific paper

https://doi.org/10.17559/TV-20240708001835

A Context Aware Security Model for Preventing Relay Attacks in NFC Enabled Mobile Devices

Davut Cavdar orcid id orcid.org/0000-0003-4538-4151 ; Middle East Technical University Ankara, Turkiye *
Emrah Tomur orcid id orcid.org/0000-0001-8985-4974 ; Nokia, Munich, Germany
Aysu Betin Can ; Computer Science - Colorado School of Mines Colorado, USA

* Corresponding author.


Full text: english pdf 968 Kb

page 1336-1346

downloads: 571

cite


Abstract

Near Field Communication (NFC) is widely used in mobile applications, yet relay attacks remain a significant security risk, especially in access control systems. Existing countermeasures, such as distance bounding, ambient sensing, and RF fingerprinting, either lack adaptability or fail to provide comprehensive protection at the application layer. In this study, we propose M-CARBAC, a context-aware access control model designed to prevent relay attacks in NFC-enabled mobile devices. Unlike prior solutions, M-CARBAC integrates dynamic contextual verification, formal security definitions, and adaptive access control policies, ensuring that captured credentials remain invalid if relayed. A formal coverage analysis confirms that the model correctly evaluates all possible access requests. Performance tests conducted on an NFC-based access control testbed demonstrate that M-CARBAC effectively mitigates relay attacks while maintaining a reasonable computational overhead. Compared to existing solutions, our model offers a more robust and scalable approach for securing NFC transactions. These findings highlight M-CARBAC's potential for enhancing the security of mobile-based access control systems against evolving threats.

Keywords

access control; authentication; context aware; mobile device; near field communication (NFC)

Hrčak ID:

332838

URI

https://hrcak.srce.hr/332838

Publication date:

29.6.2025.

Visits: 1.027 *