EMZETT.
Login

NFC

In short: Near Field Communication — a radio standard for exchanging data over very short distances (a few centimetres), known above all from contactless payment.

In more detail: Based on the same basic technology as RFID, but standardised for bidirectional communication between two active devices (e.g. smartphone to smartphone) instead of only reader to passive tag. The very short range is a deliberate security feature — an attacker would have to get extremely close to eavesdrop.

In Depth

Three operating modes

NFC works at a frequency of 13.56 MHz with a range of typically less than 4 cm and supports three operating modes: card emulation (the smartphone poses as a contactless card, e.g. for payment apps or digital IDs/tickets), reader/writer mode (the device actively reads passive NFC tags, e.g. on posters, products or smart home stickers that trigger an action when tapped) and peer-to-peer mode (two active devices exchange data directly, e.g. when quickly sharing a contact or Wi-Fi credentials between two smartphones). Unlike pure RFID, which usually only reads a passive tag one-way, NFC can therefore also let two active, equal devices communicate with each other.

Contactless payment in detail

Contactless payment (debit/credit card via NFC or Apple/Google Pay) runs on the EMV contactless standard in the background, which generates a one-time, cryptographically signed code for each transaction (“dynamic data authentication”) — even if an attacker could record a transaction completely, this code couldn’t be reused for a second payment, unlike a simple card number. Digital wallets (Apple Pay, Google Pay) add a further layer of security: the actual card number is never transmitted via NFC, only a device-specific token (“device account number”), which can be blocked centrally if the smartphone is stolen, without having to block the physical card itself.

Security and relay attacks

The extremely short range is a deliberate security feature — an attacker would literally have to hold their reader within a few centimetres of the card or smartphone to read any signals at all. So-called relay attacks are therefore more relevant in practice: an attacker places a small device close to the victim (e.g. in their bag) and a second device close to the card terminal, and the two “relay” the signals in real time over a mobile or Wi-Fi connection — to the two real endpoints it then looks as if they were right next to each other, although they’re actually far apart. Modern contactless payment systems counter this with, among other things, timing checks (the response time of a relay attack is minimally but measurably longer than with real proximity) and transaction limits without PIN entry.

See also: RFID, Radio