Go top
Paper information

Clonable key fobs: Analyzing and breaking RKE protocols

R. Gesteira-Miñarro, G. López, R. Palacios

International Journal of Information Security Vol. 24, nº. 3, pp. 150

Summary:

The automotive industry has been a target for cyber criminals for decades. New regulations have come into force in the automotive industry and manufacturers must take cybersecurity into account. One of the most interesting vehicle systems is the Remote Keyless Entry (RKE) system, which allows users to lock and unlock their cars, among other actions, with a remote control integrated in the car key. If this system is compromised, a malicious user could gain access to a vehicle remaining unnoticed. This paper presents the identification and analysis of a vulnerability in an RKE protocol that can be exploited to gain access to the car at any time, thus cloning the key fob. The reverse-engineering methodology used to uncover the vulnerability is outlined, along with other tested vehicles to show its applicability. A relevant aspect of the research is the fact that only open-source tools and available commercial hardware are needed to perform the analysis. This black-box approach is equally valid to learn RKE protocol features, without the need to extract and analyze ECU firmware, which is considerably more expensive. As a result, a detailed analysis of eight protocols from different manufacturers is shown and they are compared from a cybersecurity point of view, with one of them being totally broken.


Spanish layman's summary:

Una vulnerabilidad en un sistema RKE permite clonar el mando y acceder al vehículo sin ser detectado. Este trabajo detalla un método de ingeniería inversa con herramientas abiertas, analizando ocho protocolos RKE, uno de ellos completamente comprometido.


English layman's summary:

A vulnerability in a Remote Keyless Entry (RKE) system enables key fob cloning and undetected vehicle access. This paper details a black-box reverse-engineering method using open tools, analyzing eight RKE protocols, one found to be entirely compromised.


Keywords: Remote keyless entry; Radio frequency; Reverse engineering; Cybersecurity; Vehicle


JCR-JIF Impact Factor and WoS quartile: 5,000 - Q1 (2025)

DOI reference: DOI icon https://doi.org/10.1007/s10207-025-01063-7

Published on paper: June 2025.

Published on-line: May 2025.



Citation:
R. Gesteira-Miñarro, G. López, R. Palacios, "Clonable key fobs: Analyzing and breaking RKE protocols", International Journal of Information Security, Vol. 24, nº. 3, pp. 150, June 2025. [Online: May 2025] doi: 10.1007/s10207-025-01063-7

    Research groups:
  • Instituto de Investigación Tecnológica (IIT)
    ODS:
  • Goal 9: Industry, innovation and infrastructure
  • Goal 11: Sustainable cities and communities

pdf Preview
Request Request the document to be emailed to you.