NearFieldCommunicationNFC AtechnicalOverview
NearFieldCommunicationNFC AtechnicalOverview
net/publication/283498836
CITATIONS READS
11 41,446
1 author:
SEE PROFILE
Some of the authors of this publication are also working on these related projects:
DigiBuild: Improving the life-cycle value of buildings, Digitalization of performance-focused business View project
All content following this page was uploaded by Naser Hossein Motlagh on 05 November 2015.
FACULTY OF TECHNOLOGY
TELECOMMUNICATION ENGINEERING
Master´s thesis for the degree of Master of Science in Technology submitted for inspection,
Vaasa, 28th of May 2012.
Acknowledgement
This thesis work has been done during the year 2011- 2012. It took me a while to study this
interesting new technology which gave me a deep understanding of the topic.
Finally, I would like to thank my family specially my parents who they always give me
confidence and hopes when I meet difficulties and problems. Thanks to all my family, my
classmates and my friends for all their help and support and making last few years full of
memories and achievements.
ABBREVIATIONS ................................................................................................................ 8
ABSTRACT ........................................................................................................................... 9
1. Introduction to wireless communication.......................................................................... 10
1.1 Introduction to NFC .................................................................................................. 10
1.2 Introduction to RFID ................................................................................................ 12
1.3 Thesis Objectives ...................................................................................................... 13
2. RFID technology overview .............................................................................................. 14
2.1 Components of RFID system.................................................................................... 14
2.2 Classification of RFID systems ................................................................................ 15
2.3 RFID coupling mechanism ....................................................................................... 17
2.3.1 RFID backscatter coupling .................................................................................. 19
4.5.2 High Rate Data Transmission Using 212kbps and 424 kbps ............................... 45
Figure 1.1 Distance and data rate difference of NFC with other existing wireless
technologies ......................................................................................................................... 11
Figure 2.1 The three main components of a RFID system ................................................... 15
Figure 2.2 RFID family tree ................................................................................................. 16
Figure 2.3 Idea of backscatter coupling ............................................................................... 19
Figure 2.4 Operating principles of a backscatter transponder .............................................. 20
Figure 2.5 Capacitive coupling mechanisms in close coupling system using two parallel
capacitive surfaces ................................................................................................................ 21
Figure 2.6 The inductive communication between reader and a tag using coils .................. 22
Figure 2.7 Internal circuits of the communication devices and power supply of transponder
from energy of magnetic field generated by the reader ........................................................ 23
Figure 3.1 Lines of magnetic flux are generated around every current carrying conductor 29
Figure 3.2 Lines of magnetic flux around a conductor and a cylindrical coil ...................... 30
Figure 3.3 Relationship between magnetic flux ɸ and flux density B ................................. 32
Figure 3.4 Definition of inductance L .................................................................................. 33
Figure 3.5 The definition of mutual inductance by the coupling of two coils through a
partial magnetic flow. ........................................................................................................... 34
Figure 3.6 Induced electric field strength E in different materials from to bottom are: metal,
surface, conductor loop and vacuum .................................................................................... 36
Figure 3.7 Equivalent circuit diagram for magnetically coupled coils................................. 37
Figure 4.1 Manchester Coding ............................................................................................. 42
Figure 4.2 Modified Miller Code ......................................................................................... 42
Figure 4.3 Pulse shape of 100% ASK modulation ............................................................... 44
6
Table 2.1 Differences between active and passive mode RFID systems ............................. 17
Table 2.2 Comparison of power resource of passive, active and semi passive tags ............ 25
Table 2.3 Common RFID operating frequencies and characteristics .................................. 26
Table 2.4 RFID standards for item management (Air interface) (RFID 2002) ................... 28
Table 4.1 Definition of the divisor....................................................................................... 40
Table 4.2 NFC Communication Modes between Active and Passive devices. ................... 41
Table 4.3 Definition of time intervals shown by Figure 4.3. ............................................... 44
Table 4.4 Definition of time intervals in Figure 4.4. ........................................................... 46
Table 4.5 Command Set....................................................................................................... 52
Table 4.6 Command set for frame format shown in Figure 4.11 ......................................... 53
8
ABBREVIATIONS
UNIVERSITY OF VAASA
Faculty of Faculty of technology
Author: Naser Hossein Motlagh
Topic of the Thesis: Near Field Communication
Supervisor: Mohammed Elmusrati
Instructors: Mohammed Elmusrati
Degree: Master of Science in Technology
Department: Department of Computer Science
Degree Programme: Degree Programme in Telecommunications
Engineering
Major of Subject: Telecommunications Engineering
Year of Entering the University: 2009
Year of Completing the Thesis: 2012 Pages: 87
ABSTRACT
Near Field Communication (NFC) technology is a new wireless short range communication
technique for data transmission between intelligent devices such as mobile phones by
integrating a small NFC reader into the cellular phones. This new technology supports the
communication link within distance of up to 4 cm. NFC developed over Radio Frequency
Identification (RFID), where it uses magnetic field induction to establish a communication
link between devices. The main purpose of developing NFC is for the useful application it
provides such as wireless payment and ticketing, electronic keys, identification and so on.
Applying NFC for these matters is beneficial because of the peer-to-peer communication
which exists behind it. For example this technology prepares the possibility of quick set up
a Bluetooth or a WLAN connection without any manual configuration. Also wireless
payments and identification will be applied worldwide in near future using contactless
feature of NFC. The purpose of this thesis is to review the technical aspects of NFC
technology such as Radio Frequency (RF) containing Modulation techniques, Underlying
Protocol and Frame format, Applications and finally the Security of NFC will be discussed.
Near Field Communication technology (NFC) was found and initiated by Sony and Philips.
NFC is an upcoming technology developed over RFID, in a way that it consists of an
interface and protocol are based on RFID which makes NFC device to a part of this
standard and compatible with existing RFID technology. It is a new technology that enables
a contactless, wireless communication link between devices close to each other less than 4
centimeters for sharing information at a maximum data rate of 424kbps where the
difference with the other existing wireless technologies is shown in Figure 1.1.
11
Figure 1.1 Distance and data rate difference of NFC with other existing wireless
technologies (NFC Forum)
This communication can be either active, passive or both active devices, NFC works by
utilizing magnetic coupling between devices. NFC is a new paradigm for the vast majority
of cell phone users and is emerging as a near-term reality (Fischer 2009). This technology
has a growing business potential technology. For instance it allows people to use their cell
phones to pay their travel tickets or pay for their purchases instead of using their bank
cards. Also there have been many applications developed by this new technology such as
electronic keys, identification, receiving and sharing information or applying it as a set up
service. NFC provides the possibility that users can share business cards, make
transactions, access information from smart posters or provide credentials for access control
systems with a simple touch. Therefore it can be said that NFC provides easy connections,
quick transactions, and simple data sharing. The main technical feature of NFC is that it
complements many wireless technologies, in a way that it utilizes the key parameters and
elements in the existing standards for contactless card technology. The complementing
features of enables NFC to be compatible with other existing contactless infrastructure and
able the users to use one device with different systems (NFC Specifications). As mentioned
NFC is initiated over RFID then it has more communication possibilities. The main
characteristic that differentiates NFC from RFID is that the new technology prepares
12
bidirectional data transmission between NFC equipped devices. For the communication
between the two devices it is just enough to bring them close together or make them touch
physically.
Then the NFC protocol automatically establishes peer-to-peer link where the devices can be
in passive or active mode. In the passive mode only one of the devices generates a RF field
while the other device applies the load modulation for data transmission where in later
chapters the active and passive modes and the modulation techniques will be discussed
Also to get the knowledge about NFC it is required to understand the underlying
infrastructure of RFID.
The use of RFID first started over six decades ago by British military in World War II in
order to identify army objects such as planes and it was part of refinement of radar. In
1960s RFID was first considered as a solution for commercial use and in 70s and 80s, it
was developed for commercial applications. Also later in 1998 a research at Massachusetts
institute of technology (MIT) started to find new ways to track and identify objects moving
in different physical locations. Nowadays RFID is developed to enable systems to be used
for low cost commercial applications. The first developments of RFID were electronic
surveillances called tags. RFID systems consist of tags, interrogator or reader. A tag is a
microchip attached to an antenna and packaged so it can be attached to an object. The tags
obtain a unique serial number and their identification number which this enables it to
communicate (receive and send signals) with the reader. The duty of the interrogator
(reader) is to emit electromagnetic waves from the antenna in a way that the sent waves are
absorbed by the tag and used as energy to power the tag’s microchip in order to enable tag
to send a signal which includes the identification number back to the reader. Additionally
there are two types of tags, High Frequency (HF) tags which can be integrated at a distance
of up to 0.8 meter while Ultra High Frequency (UHF) can be red up to 15 meters from a
13
reader. There for comparing HF and UHF tags, HF tags provide more security functionality
than the other one by using larger silicon chips (RFID Products).
Furthermore tags can have two modes active or passive. In short to explain, when a tag uses
transmitter to return information from the reader it is in active mode where most of the
active tags are battery powered. Passive tag is the one that does not have the power source
and it uses the transmitter electromagnetic waves as its resource.
This thesis report will start with the description of the RFID since Near Field
Communication was developed based on that and then the report will cover the overall
knowledge about NFC technology. The report will start with introduction to NFC and
continue by describing the communication technology with RF and digital interface and
modulation. During the thesis chapters the NFC standard will be described in details and it
will cover the technical aspects of the technology such as Electromagnetic fields, Radio
Frequency (RF), Data transfer, Modulation, Coding Schemes, Protocols, Frame Format,
Applications, Security issues of the technology. Finally the thesis will be summarized as a
conclusion of this work and few topics will be point out for future research.
14
the reader. A reader which is called interrogator is a read and write device. It is composed
of an antenna, an RF electronic module for transmitting and receiving signals and a control
electronics module. Another component of RFID is the controller which mainly is a
computer or a workstation which obtains a database and the required software.
Data
Classification of RFID systems are according to the properties of the data carrier
(transponder or tag). RFID systems classification is based on two main modes which they
are called Active and Passive modes. This classification is shown in Figure 2.2; the figure
also represents the most common RFID system frequency categories which will be
explained in later in this chapter.
16
In active communication mode, active tags have their own power supplies typically using
an internal battery which generate their own Radio Frequency signals for data transmission.
Passive tags do not have a power supply and they are dependent on the readers in a way
that they acquire their own power produced by the field generated by the readers. Therefore
it is clear to understand that passive tags are much smaller and cheaper than active ones.
Also semi passive or semi active tags have a battery to power the microchips. In a way that
semi passive and semi active use a battery to supply the internal operation of the tag but
they rely on the RFID reader to supply the power to transmit the signal to the reader. The
features of these two communication modes result in some advantages and disadvantages
that obtained from the major differences between Passive and Active RFID modes. The
summary of these difference are represented in Table 2.1.
17
Table 2.1 Differences between active and passive mode RFID systems
To create the two discussed passive and active modes in the communication link a
mechanism which is called coupling technique is required. Coupling mechanism is the way
of communication between RFID tag and reader. There may be different ways for RFID
transponder and reader that can communicate but here this thesis report has focused on
three main coupling methods which they are:
In addition it is important to consider that the type of coupling method is applied according
to the intended application. Each of these methods has its own feature and differs from the
others. The type of coupling method effects different aspects of RFID system such as
communication distance, frequency range and other elements of RFID hardware. The range
or the communication distance of RFID system can be categorized into three areas:
Communication of RFID systems on very short range known as close coupling where the
range of these type of coupling are up to 1 centimeter. This means that the tag must be
pressed against the reader device and this short distance results in some benefits in case of
energy absorption by the tag because the tag can gain large amount of energy from the
magnetic field. Another advantage of this coupling provides high security for the systems
that are in need of this requirement. Furthermore close range communication inductive and
capacitive methods are used.
Remote coupling typically operate in the range between 1 centimeter and 1 meter. This
range usually applied with passive tags and similar to close coupling this range is uses
inductive and capacitive methods.
Long range RFID communication is used for longer distances than close and remote
couplings. Normally the distance range is between 1 m and 10 meters and this range uses
the higher frequency which is specified for RFID. Also unlike the previous ranges this
coupling applies backscatter coupling method. Therefore this higher distance specifies the
sort of tags and communication modes which in this case typically the system contains tags
which act in long range with very low power or active tags which contain a power source
such as battery. Additional to all the ranges mentioned above systems with greater
distances than 10 meters exist.
19
RFID backscatter coupling operates outside of the near field region in a way that this
coupling method, the reader propagates radio signals and then the tag receives the signal
and applies it by using part of the received signal as its own power resource and reflecting
back some energy as the tag’s response toward the reader as the ‘Data’. The following
Figure 2.3 illustrates this concept.
The behavior of tag when replying the readers signal seems to be interesting. The way how
the tag responds readers signal all is dependent on the properties of the tag and some
essential factors such as cross sectional area, antenna properties and so on. Antenna play a
very important role in receiving and radiation of the signal and how this radiation is done
depends on antenna properties by adding or removing a load resistor across the antenna.
Furthermore for full duplex communication of the system sometimes a directional coupler
is applied to separate the transmitted and received signals in the system. The design of the
transponder electronic circuit has the main role in any communication system; therefor here
we catch a glimpse on the electronic design of the transponder (Finkenzeller 2003). Figure
2.4 shows the total idea of a transponder electronic circuit and power transmission between
communicating devices.
20
As it is clearly shown in the Figure 2.4 above power P1 is emitted by the signals from the
reader antenna and just a small portion of this energy reaches the transponders antenna.
Then this power as High Frequency voltage is supplied to the antenna connection and after
recertification by the diodes (D1 and D2) this power can be as a turn on voltage for the
deactivation and activation of the power saving which this is called power down mode. It is
obvious that for this low provided energy for the circuit the diodes must be low barrier
Schottky diodes, where this types of diodes lower energies and they have low threshold
voltage. After P1 is supplied into the circuit a proportion of the incoming P1 is reflected by
the antenna and returned as P2 as the energy source for the reflecting signals. Furthermore
the impedance of the chip is ‘modulated’ by switching the chip’s FET. Also as formerly
mentioned the reflection features of the antenna can be influenced by changing the load
resistor connected to the antenna, this is done due to transmitting data from transponder to
the reader. The reflected power P2 from the tag radiates into free space and just a small
proportion of this energy is received by the antenna of the reader. This energy witch is in
form of the signal “Data” travels in backwards direction by the readers antenna, where this
can be decoupled using a directional coupler to the receiver input of the reader
(Finkenzeller 2003).
21
RFID capacitive coupling is applied for short range communication for data transmission
whenever a close range coupling is required. This mechanism utilizes the capacitive effects
to provide the coupling between the communicating devices. Referring to Figure 2.5 it is
shown that in this mechanism the plate capacitors are constructed from coupling surface
which are separated from each other and these are designed and equipped in both
transponder and reader so that when a transponder is inserted, they become parallel to each
other.
Figure 2.5 Capacitive coupling mechanisms in close coupling system using two parallel
capacitive surfaces
RFID capacitive coupling has the highest performance when smart cards by applying the
standard ISO 10536 and inserting it into a reader and it is because the card becomes close
to the reader. In this mechanism capacitive coupling uses electrodes to provide the needed
coupling instead of having coils or antenna. Therefore it is the responsibility of the
capacitors by providing capacitance characteristics between the transponder and the reader
to transmit the signal. It works so that the generated AC signal by the reader is taken and
rectified by the transponder and applied as the device power resource of the tag and similar
22
to the previous coupling the data is transmitted to the reader by the modulating load
(Finkenzeller 2003).
RFID inductive coupling mechanism which is defined by ISO 15693 standard is a coupling
technique that transmits the energy from a circuit to another via mutual inductance between
the two circuits. The Idea of the inductivity is shown in Figure 2.6 which both transponder
and reader apply the inductivity feature for the communication and data transmission.
Figure 2.6 The inductive communication between reader and a tag using coils
The operation of the inductive coupling is so that when a transponder is located near by the
reader, the transponder antenna coil is coupled by the field produced by the reader antenna
coil. The field will cause the production of voltage in the tag and will be rectified and
applied for the power of the transponder’s circuit. Also for modulation the transponders
circuit alternates the load on its coil where this can be detect by the reader as outcome of
mutual coupling. As far as the RFID inductive mechanism is a near field technique the
distance between the coils must be kept in the effect range where generally it is considered
as 0.15 wavelength of the applied frequency. Hint that inductive coupling applies the low
23
frequency this means the frequency must be under 135 kHz. In addition this type of
coupling unlike the capacitive and similar to backscatter coupling electronic circuits are
used in transponder and the reader so having a look at these internal circuits of these two
devices shown by Figure 2.7 will help to better understanding of this coupling mechanism
(Finkenzeller 2003).
Figure 2.7 Internal circuits of the communication devices and power supply of transponder
from energy of magnetic field generated by the reader
the resonant set up in the parallel resonant circuit. Also the on and off switch of the load
resistance at the transponders antenna influences the voltage to alternate at the reader’s
antenna coil and if the on and off switch of the load resistor is controlled by the data,
therefore this data can be transmitted to the reader from the transponder where this type of
data are called “Load Modulation” (Finkenzeller 2003) where modulation techniques in
later chapters will be discussed.
As already discussed during previous parts of the thesis, transponders may obtain their
power in various ways. Definitely the power resource plays the main and essential role in
the properties of a tag since the energy source of this device specifies the life time, cost and
mainly the tag’s potential read range; also this factor determines the functionality that a tag
can provide. Furthermore as we already talked about the different modes of an RFID, we
have three different modes which they are active, passive and semi passive or semi active;
consider that these modes have direct relation to the transponder’s power resources. Active
tags obtain their own power like a battery in this case the tag may start and initiate
communication with a reader or even with other active tags. Semi passive transponders
have an internal battery but unlike the active tags cannot initiate communications. So to
establish the communication between communicating devices these types of tags are
dependent on the readers to be able of acting. Passive tags do not have their own power
source and then they are not capable of initiating the communication. These sorts of tags
obtain their required energy for acting by harvesting it from an incoming RF signal where
at low frequencies this energy is received inductively and at higher frequency ranges the
energy is obtained capacitive. This different tag type with different way of providing power
source affects the communication range where semi passive offer a longer reader range
than passive attacks but they have higher cost while the passive tags have the shortest
25
range. Also this is clear that using batteries cost and this cost is different in different types,
Table 2.2 shows the summary of this comparison.
Table 2.2 Comparison of power resource of passive, active and semi passive tags
RFID systems operate in the unlicensed radio frequency bands known as ISM (Industrial,
Scientific and Medical) but the precise frequencies which are defined for RFID may vary
depending on the regulations in different countries. There are several frequency bands
Europe, Japan and the United states have all designated as ISM, and most the RFID
systems operate at these frequencies. These frequency categories and most usual RFID
system frequencies are listed in Table 2.3. In general the operating frequencies are
organized into four main frequency bands of LF, HF, UHF and Microwave where these
frequencies are shown in Table 2.3. This table represents the frequency bands applied in
RFID also some other information such as the amount of data rate by each one of these
bands furthermore the characteristics and typical applications.
26
The most important frequency bands which are defined for RFID systems are 0 – 135 kHz,
ISM frequencies around 6.78 MHz, 13.56 MHz (NFC), 27.125 MHz, 40.68 MHz, 433.92
MHz, 869.0 MHz, 915 MHz (not in Europe), 2.45 GHz, 5.8 GHz and 24.125 GHz
(Finkenzeller 2003). Consider that the frequency band under 135 kHz is not reserved for
ISM band. The defined frequency bands in real and actual communication range alternates
27
a lot dependent on some factors such as the operating environments and antenna design.
Those RFID systems which apply LF and HF frequencies are used for near field
communication and the inductive coupling mechanism which already was discussed. UHF
and higher frequencies are used for far field communication and for the backscattering
coupling. Talking about far field means that this type of communication is based on
electronic radio waves, i.e. the reader emits continues signal that is sent back from the
transponder’s antenna.
An RFID system applies few numbers of standards where none of them has been
universally accepted for this matter the industries which involve RFID applications
encounter with some complexity. These standards may be categorized into four levels of
international, national, industry and association level. These standards can be applied to
cover four key areas of RFID application:
Air interface standards which is used for basic tag to reader communication.
Data content and encoding i.e. the format of the codes used in tags.
Conformance which means testing the RFID system.
Interoperability between applications and RFID system.
There are several standards define the development of RFID technologies such as:
International Organization of Standardization (ISO)
Electronic Product Code (EPC)
European Telecommunication Standards Institute (ETSI)
Federal Communication Commission (FCC)
Each of the standardization organization mentioned above defines set of standards for
different RFID applications while ISO supports the required standard for RFID frequencies
under series of ISO 18000 which known as Air Interface Family.
28
The complete set of these standards which is released in 2004 where include different
specifications that cover all popular frequencies including 135 KHz, 13.56 MHz, 860 - 930
MHz and 2.45GHz are shown in Table 2.4 (RFID 2002).
Table 2.4 RFID standards for item management (Air interface) (RFID 2002)
It is good to mention that there were related standards related to RFID technology such as
ISO 11785 applied for cattle tracking systems which is defined for read range of 10 cm,
ISO 14443 used for tag based payment also called proximity cards, ISO 15693 used for
electronic toll collection called vicinity where the sets ISO 14443 and 15693operate at
13.56MHz for High Frequency and defined for the read range of 100 to 150 centimeters.
29
To understand Near Field Communication one might need to understand the underlying
physical principles of related technology. In addition in previous chapters it is mentioned
that the newly developing NFC technology is extension of RFID system. RFID utilizes
electromagnetism for communication and in order to understand the process of power and
data transfer, in this chapter the theory of electromagnetic waves and the principles of
inductive, capacitive coupling will be reviewed.
Figure 3.1 Lines of magnetic flux are generated around every current carrying conductor
In the general form we can say that: ‘the contour integral of magnetic field strength along a
closed curve is equal to the sum of the current strengths of the currents within it’ and it is
shown by the equation (3.1). To calculate the field strength H of any type of conductor this
equation is applied (Finkenzeller 2003).
30
∑ ∮⃗ ⃗⃗⃗⃗ (3.1)
The following Figure 3.2 is an example shows that how the magnetic flux behaves when a
current passes a conductor. The conductor loops are used as magnetic antennas to produce
the magnetic alternating field in the devices of inductively coupled RFID system.
Figure 3.2 Lines of magnetic flux around a conductor and a cylindrical coil
Also in a straight conductor the field strength H along a circular flux line at a distance r is
constant. For the straight conductor H can be calculated as:
(3.2)
The path of field strength along the x axis of a round coil which is the same as conductor
loop can be calculated by using equation (3.3). Consider that the magnetic field strength H
decreases when the measuring point moves away from the center of the coil axis this is
shown by x in Figure 3.2 and then the field strength reduces by 60 in the near field of
the coil.
(3.3)
√
31
Where in this equation N is number of windings, r is the circle radius and x is the distance
from the center of the coil in the x direction. The condition of the validity of this equation is
when that and . In addition the transition into the electromagnetic far field
happens when x exceeds . Also at distance zero which is the center of antenna
(3.4)
Furthermore to calculate the magnitude field strength path for a rectangular conductor loop
with side lengths at distance of x the following equation (3.5) is applied.
(3.5)
√
The total number of magnetic flux lines which pass through the inside of cylindrical coil is
denoted as magnetic flux. The magnetic flux is defined by measurement of the amount of
magnetic field which passes via a given surface and shown by with the unit webers
, magnetic flux density shown with B with the unit Teslas (T) and this is a variable
related to area A in square meters ( ) where magnetic Flux is given by the equation (3.6)
(3.6)
32
Figure 3.3 shows the material relationship between flux density B and field strength H.
Also the relationship between flux density B and field strength H is defined by equation
(3.7).
(3.7).
Where in this equation is the magnetic field constant with the value of
which describes the permeability of a vacuum. Also is the relative permeability and
explains the permeability of a material if it is greater or less than .
3.3 Inductance
Always magnetic field is generated when current flows in a conductor and if the conductor
is in the form of a coil the magnetic field will be stronger. Any coil has N loops of the same
are A when the same current I flows in it. The total flux which is shown by is the sum of
the flux generated by N number of coil loops is defined by the following equation (3.8).
33
∑ (3.8)
The relationship of the total magnetic flux and the current is called inductance L and
represented by the equation (3.9) where the inductance of a conductor loop depends on the
geometry of the layout and the permeability of the medium that the flux flows through it.
Also this representation is shown in Figure 3.4.
(3.9)
Mutual inductance is the physical principle that an RFID system works based on that which
RFID relies on this phenomenon for both power and data transfer. Mutual inductance
explains the coupling of two circuits with a magnetic field where the unit and dimension of
it is the same as the inductance which explained in previous part. It works in a way that if
second conductor coils loop with the area located in vicinity of the first conductor loop
with the area which current flows in it will be affected by the magnetic flux generated
by .
34
This will cause some portion of the flux to flow through the second coil where this flux is
called coupling flux that connects the two coils inductively. The idea of mutual inductance
is represented in Figure 3.5.
Figure 3.5 The definition of mutual inductance by the coupling of two coils through a
partial magnetic flow.
In mutual inductance the quality of the inductive coupling depends on the geometry of the
two coils, their position relative to each other and the permeability of the medium between
them. The mutual flux which passes through both coils is called the coupling flux and
shown by and the mutual inductance is shown by and this is defined as the ratio of
which passes through the second coil to the current in the first coil and represented by
the following equation (3.10).
∮ (3.10).
Consider that the same relationship works the other way around, i.e. a current in the
second coil will generate a magnetic field that will induce a current in the first coil through
the coupling flux . The relationship between the mutual inductance can be shown by the
equation (3.11).
35
(3.11)
In addition the mutual inductance magnetic field between two coils is given by the
following equation (3.12).
(3.12).
(3.13)
√
Hint that the validity of the equation (3.13) depends on if the x axis of the two coils lie on
the same plane and .
Coupling coefficient is the way of measuring the efficiency of the inductive coupling
between two conductor coils. Coupling coefficient is given by the equation (3.14).
(3.14)
√
In a way that and if the value of k is close to 0, due to the distance system will
have high decoupling, if the value of k is close to 1, system will have high coupling and if
the value of k is equal to 1 then both of the coils will be subject to the same magnetic flux.
36
Any change to the magnetic flux ɸ generates electric field strength where this feature of
the magnetic field is described by Faraday’s law. The effect of the electric field generated
in this manner is dependent on the material properties of surrounding area; Figure 3.6
shows some of these possible effects.
Figure 3.6 Induced electric field strength E in different materials from to bottom are: metal,
surface, conductor loop and vacuum
Inducting electric field in vacuum causes the field strength E to give rise to an electric
rotational field. Open conductor loop causes an open voltage build up across the ends of an
almost closed conductor loop which is normally called induced voltage. Also metal surface
causes free charge carries to flow in the direction of the electric field strength. Faraday’s
law in its general form is given by the equation (3.15).
∮ (3.15)
37
Furthermore for a coil with N windings this equation can be represented as (3.16).
(3.16)
Also a time variant current in the first coil generates a time variant magnetic flux
which leads to a voltage being induced in both coils. It is possible to differentiate into
to two cases of self-inductance and mutual inductance. For self-inductance the flux change
generated by the current change induces a voltage in the same conductor circuit but for
mutual inductance, the flux change generated by the current change induces a voltage in the
adjacent conductor circuit. Figure 3.7 shows the equivalent circuit diagram for coupled
coils where in an RFID system can be the transmitter antenna of the reader and
assumed to be the target antenna.
In this coupling mechanism the current consumption of the chip is symbolized by the load
resistor . A time varying flux in the first coil induces a voltage in the second coil
due to the mutual inductance M. Also due to the current, a voltage drop is created across
38
the coil resistance and this means that the voltage can be measured across .
Furthermore and extra magnetic flux against the magnetic flux is generated because
of the current which is flowing through . This action and reaction is presented in
following equation (3.17).
(3.17)
And since and are sinusoidal alternating currents the previous equation can be
represented as (3.18).
(3.18)
Also if is replaced by in (3.18) then the equation for can be solved like (3.19).
Where (3.19)
39
For the first time the development and initiation of NFC technology was done by Sony and
Philips. This new technology includes an interface and a protocol which is the developed
on top of RFID and this is the reason that NFC device is compatible with existing RFID
technology.
The development of new technology differentiates it from the existing one with some new
additional characteristics. First it provides the possibility of bidirectional data transfer and it
also provides peer to peer communication. Where in a passive mode, only one device
produces the required Radio Frequency for the communication and the other device utilizes
the Load Modulation for data transmission and furthermore, NFC supports data transfer
between the both active devices.
Near Field Communication is a short range and standard based wireless technology which
operates in globally available unlicensed of 13.56 MHz frequency band ( ) and the
bandwidth of the system is ±7kHz. The technology supports the data transfer with the
rates of 106kbit/s, 212kbit/s and 424kbit/s and still it has potential of higher data rates
where are expected in the future. Furthermore the radio transmissions by the technology are
half duplex where the same channel is used for both communicating devices. Also to
prevent the collision in radio transmission they apply CSMA protocol which it is Carrier
Sense Multiple Access and it means sense or before transmit or listen before to talk.
NFC is a short range because it is designed for the communication up to 20 centimeters for
the maximum range but typically it is used within less than 10cm and practically
connection occurs between two NFC devices when they brought to about 4 centimeters of
another. This short range provides a high advantage in the communication which it is the
security and this feature will be discussed in later chapters.
40
The bit duration in NFC depends on the communication mode and the data rate and a
divisor which is defined for the specific mode and the data rate. In addition always the
initiator which initializes the communication chooses the initial bit rate. These modes and
divisors are shown in Table 4.1 and the bit duration is calculated by the equation (4.1)
(NFC Specifications).
(4.1)
Where is the bit duration, is the carrier frquancy, and D is the divisor.
NFC enabled devices can communicate in two different modes which they are active and
passive modes. A device that can generate its own radio frequency field is called an active
device whereas a device which needs to use inductive coupling for data transmission is
called a passive device. Active communication mode occurs when the operation is
conducted between two active devices and passive communication mode happens when the
operation happens between an active and a passive device. In addition applying active
41
mode communication both of the initiator and target devices follow the same and similar
specifications such as speed of data transmission. Table 4.2 shows these communication
modes clearly.
For communication establishment, the device that starts the communication is called
Initiator and the other communicating device that receives the Initiators request and sends
back the acknowledgment is called the Target. In addition during the communication the
mode cannot be changed or as long as the established one is terminated and this does not
mean that transmission speed cannot be speeded up and this can be done by performing a
parameter change procedure. As far as the transmission requires energy, so it is not a good
idea for the devices that use battery power such as mobile phones to act as active device
and its more suitable to act as the passive device (ISO 2004).
Manchester Coding: This coding scheme is the most common data coding method is
applied nowadays. The transmission using Manchester coding consequently happens in the
middle of each bit period. This coding method depends on two possible transitions at the
middle of a symbol period in which a low to high transmission expresses a 0 bit and a high
42
to low transmission represents a 1 bit. The idea of bit expression is shown in Figure 4.1
(Paus 2007).
Modified Miller Coding: This coding method defines 0 bits and 1’s by the position of a
pulse during one bit period; the bit representation is illustrated in Figure 4.2.
As the Figure 4.2 shows, in the coding scheme the start and initiation of the communication
happens at the start of the bit duration where a pulse may occur. For bit 1, the pulse may
happen in the second half of the bit period where the transition happens in the middle of the
bit period from high to low. For 0 bits a pulse may occur at the beginning of the bit period
where if 0 bit follows a 1 bit any pulse does not happen during the 0 bit coding. Also in the
end of the communication 0 followed by one bit duration without modulation. Furthermore
43
in case of No information, the signal may be coded with at least two full bit durations
without modulation.
The role of initiator and target allocation is important in NFC communication and data
transmission. Always the initiator is the device who is willing to start the communication
and the target is the one who receives the initiator’s communicator’s request and sends back
the reply. Furthermore in active mode, the features shall always be same for both of the
communicating devices i.e. initiator to target and target to initiator communication. At the
lowest data transfer speed supported by NFC, the initial bit rate shall be 106 kbps and for
the higher data transmission the bit which are used are 212kbps and 424 kbps which these
low and high rates will be discussed in two different sections.
Discussing the lowest data transfer speed applying NFC chips, the primitive and initial bit
rate is 106kbps. For this low rate transmission the initiator device may apply 100% ASK
modulation to generate the required pulses where the Figure 4.3 clears out this generation
(Ecma 2004).
44
Analysing the envelope of the carrier amplitude shows a tedium decrease to less than 5% of
its initial value and the remaining is less than 5% for the duration of . The
overshoots may still remain 90% and 110% of .
In communication the Target may find the end of the pulse when the field exceeds 5% of
and before it exceeds 60% of as shown in the Figure 4.3 by and all
these defined by time intervals in Table 4.3. Hint that this definition applies to all
modulation envelope timings.
Pulse Length
(Condition)
Maximum 3.0 1.5 0.4
Furthermore for this low bit rate of 106kbps the byte coding may be LSB and for the
transferring the data Modified Miller Coding method is applied (Ecma 2004). Also LSB
which is Least Significant Byte and it indicates a serial data transmission system that sends
LSB before all other bytes.
4.5.2 High Rate Data Transmission Using 212kbps and 424 kbps
Talking about higher data rate transmission means that NFC applies 212kbps ( or
424kbps which they are chosen by the initiator. The modulation scheme is still
ASK but with different indexes which they are 8% to 30% of the operating field in which
this is referred as 10% ASK. Figure 4.4 describes the modulation waveform and as the
figure implies the rising and falling edge of the modulation may be monotonic. In addition
the modulation for the transmission during the initialization and single device detection
shall be the same. The peak and the minimum values of the modulated signal are defined by
“a” and “b”. Also the following Table 4.4 explains and summarizes the figure below clearly
(Ecma 2004).
Byte encoding of higher data transmission shall be MSB and the coding applied
Manchester method with observe amplitude. Also the reserve polarity in the amplitude of
the Manchester symbols is allowed. The target shall respond with the same load modulation
scheme but the bit duration must be altered to the actual bit rate (Ecma 2004). Also
MSB which is Most Significant Byte and it indicates a serial data transmission system that
sends MSB before all other bytes.
Obviously applying passive communication mode means using different specification than
the active one. These differences are separated in two parties of communicator devices,
initiator and target. In passive mode, in case of initiator to target, the modulation, byte
encoding, bit representation and coding for the different bit rates is the same as in active
communication mode following the rules for different bit rates discussed in previous
sections. But in case of target to initiator communication, the target responds by Load
Modulation which generates a subcarrier with frequency of . In addition the
load modulation amplitude has to exceed a minimum value relative to the strength of the
existing magnetic field. Also bit representation is done by Manchester coding with observe
amplitude and bytes are encoded with LSB first for the lower data rate (106 kbps) and MSB
first for the high bit rates (212 and 424 kbps).
47
All the devices that obtain a NFC technology can be either in initiator or target mode where
passive devices are always in target mode. In the first step all devices are set to be in target
mode by the default but else if the application ask the device to change to initiator mode
where the application determines the mode of the communication and the transfer speed. In
case of passive mode it performs as single device detection before it starts data
transmission. The protocol flowchart for single device detection and general initialization is
shown in Figure 4.5. In addition when talking about the target mode it means the device
dose not generate any RF field and waits for the field generated by an initiator. Also a
device in initiator mode using collision avoidance tries to detect existing RF fields before
generating its own field.
The following flow chart shown in Figure 4.5 describes the general initialization and single
device detection for the active and passive communication mode at different transfer
speeds. The communication starts by initiator but while initialization, the initiator may
detect a collision when two or more targets transmit their bit patterns at the same time.
Therefore as the protocol describes the RF collision avoidance is defined to handle this
issue and in order to do not disturb the other current communications existing on the carrier
frequency, the initiator should not generate any RF field until the time the existing field is
terminated (ETSI 2003).
48
Start
Initial RF collision
Avoidance
RF Field Yes
detected?
No
Activation in Active
Activation in passive
Communication mode
communication mode
by NFCID3 (ATR)
by NFCID3 (ATR)
.
Data exchange
protocol (DEP)
De-Activation
(DSL, RLS)
Terminate
49
In the communication, the initiator always senses the medium continuously to check the
presence of other existing RF fields. If the initiator dose not detect any external RF field
within the timeframe TIDT + n × TRFW the RF field should go to switch on mode. The
following Figure 4.6 demonstrates the initial collision avoidance while initialization (ETSI
2003).
The Figure 4.6 shows a signal which is divided by different time intervals where each of
them has its own definition which they are as described below:
: is the initial guard time between switching on RF field and start to send command
or data frame where
50
Furthermore it is good to mention that the generated RF field by the initiator should be
switched off in the Active mode and in the passive mode should not be switched off.
In order to avoid collision of the data transmission by the simultaneous responding of more
than one target a Response RF Collision Avoidance is needed addition to the initial RF
collision avoidance. Following Figure 4.7 represents the response RF collision avoidance
sequence during initialization (ETSI 2003). Also consider that the incoming or outgoing
signal is called a sequence. Also the receiving device needs the required information on
when to start and stop demodulation and how to recognize a sequence. So, a sequence
always starts and ends with a specific bit pattern where later in this chapter this issue will
be discussed under the Frame section.
Also the Figure 4.7 illustrates a signal which is divided by different time intervals where
each of them has its own definition which they are as described below:
: is active delay time, sense time between RF off Initiator/Target and Target/Initiator
where ( ≤ ≤ )
51
: is the active guard time between switching on RF field and start to send command
where
This part of the thesis chapter defines the frame format used during initialization and single
device detection. Data which is transmitted between communicating devices is grouped and
formed in frames. The shape of the frame between initialization and the data transfer in
passive communication mode is different. Also the data frames are transferred in pairs in a
way that the initiator initiates the communication followed by the response of the target.
The initiator frame format consists of the start, the data itself and the end of the
communication. Figure 4.8 shows the initiator and the target frame format.
Also for the data exchange at the rate of 106kbps, standard frames are utilized, the format
of a standard frame is shown in Figure 4.10.
52
In the standard frame the start byte SB is set to be 0xF0. The length byte LEN should set to
the length of the Transport Data field plus 1. Also the value of LEN must be from the range
of 3 to 255. CMD0 and CMD1 are command bytes that are used by the initiator and the
response by the targets, these commands are described in Table 4.5 below (Ecma 2004).
Mnemonic Definition
SENS_REQ Sense Request (sent by Initiator)
SENS_RES Sense Response (sent by Target)
ALL_REQ Wakeup All Request (sent by Initiator)
SDD_REQ Single Device Detection Request (sent by Initiator)
SEL_REQ Select Request (sent by Initiator)
SEL_RES Select Response (sent by Target)
SLP_REQ Sleep Request (sent by Initiator)
Table 4.5 Command Set
Furthermore E1is applied in order to CRC checking for the frame format of 106kbps. Hint
that the LSB of each byte should be transmitted first. Each byte shall be followed by an odd
parity bit. The data frames format which are used in passive communication mode at the
rates of 212 kbps and 424 kbps are different, this frame structure is illustrated in Figure
4.11.
53
As shown in the Figure 4.11the communication starts with the preamble sequence (PA) of
minimum 48 bits with all logical “Zero” encoded. Also the SYNC byte which is the
synchronization, contains two bytes where these bytes must be set to 0xB2 and 0x4D. The
LEN byte is set to the length of the Transport Data field plus 1 and the value of LEN is an
integer number range from 3 to 255. E2 is applied for the CRC in the frame format of 212
and 424 kbps. In addition, in active communication, the frame format for initialization does
not differ from the frame format for data exchange. Also the command bytes consist of 2
bytes as shown in Figure 4.11. The first byte is CMD0 and the second byte is CMD1 and
the code of the command specifies the Request and Response according to the Table 4.6
(ETSI 2003).
Request and Respond in NFC is done by Load Modulation and it means the process of
amplitude modulating a radio frequency field by varying the properties of a resonant circuit
placed within the radio frequency field. Applying the load modulation principles allows
that the data from a passive target to be transmitted back to the reader. In a way that if a
target with a resonant frequency equal to the transmission frequency of the reader is placed
by the magnetic alternating field of the reader’s antenna, the target will be powered by the
magnetic field. Also if the load resistor is switched on and off at the target, the voltage
changes at the reader’s antenna because of the impedance changes in the target resulting in
amplitude modulation at the reader’s antenna. This will happen when the target is placed by
the near field of the reader’s antenna. Therefor for short it is said that when the initiator is
generating the RF field and the Target responds to an initiator command in a load
modulation scheme. Following Figure 4.12 demonstrates a scenario of how load
modulation is applied in passive communication mode (Philips 2011).
Figure 4.12 Targets answer to initiator using load modulation in passive communication
mode
55
are normally used. The modulated subcarrier is now applied to switch the
load resistor on and off. The best advantage of utilizing a subcarrier becomes clear when
the frequency spectrum generation comes to the consideration. Furthermore the load
modulation with a subcarrier initially generates two spectral lines at a distance the
subcarrier frequency around the operating frequency. This is illustrated in Figure 4.13.
The actual information is now transmitted in the sideband of two subcarrier lines depending
on the modulation of the subcarrier with the baseband coded data stream. In addition if load
modulation in the baseband were used, on the other hand, the sidebands of the data stream
would lie directly next to the carrier signal at the operating frequency (Finkenzeller 2003).
56
Also due to the weak coupling factor between the reader and the target antenna and the
difference between the carrier signal of the reader and the received modulation sidebands,
the targets response varies within the range 80–90 where this range is lower than the
voltage generated by the reader. This is shown in Figure 4.14. In this procedure one of the
two subcarrier modulation products can be filtered out and demodulated by shifting the
frequency of the modulation sidebands of the data stream. Consider the production of two
modulation sidebands at a distance of from the carrier frequency of the reader
where to separate the sidebands from the stronger carrier signal, bandpass filtering is
applied and then the signal is amplified at the reader due to demodulation process
(Finkenzeller 2003).
57
Analyzing the characteristics of any electromagnetic wave at any point in the magnetic
field allows the reconstruction of the message by measuring the change in the reception
power, frequency or phase position of the wave where this procedure is called
demodulation. The former classical radio technology is involved with analogue modulation
procedures. But the modulation of the electromagnetic waves can be done through different
techniques which they are amplitude modulation, frequency modulation and phase
modulation. Hint that all the other modulation techniques are derived from one of these
three sorts of techniques. The procedure applied in NFC system, the data transmission
made possible through ASK (Amplitude Shift Keying), FSK (Frequency Shift Keying) and
PSK (Phase Shift Keying) in which these methods are reviewed here in short.
58
Amplitude Shift keying (ASK) is a type of digital modulation that shows digital data in
the form of variation in the amplitude of a carrier wave, as a result of MATLAB modeling
this can be seen from the plot in the Figure 4.15. For binary levels the bit 1 is represented
by the standard carrier wave and 0 is represented by a carrier wave with zero amplitude.
The type of ASK is called 100% ASK or on-off keying and this one is the very basic type
of ASK modulation. Furthermore the percentage describes how much the amplitude is
decreased, as the example when saying 30% ASK would mean that a logical 0 reduces the
amplitude level to 70% compared to the amplitude level of logical 1.
-5
0 1 2 3 4 5 6 7 8
Time (bit period)
Original Digital Signal
1.5
1
Amplitude
0.5
-0.5
0 1 2 3 4 5 6 7 8
Time (bit period)
Phase Shift Keying (PSK) is the other type of digital modulation where it demonstrates
the digital data in form of variation of the phase of a carrier wave and as a result of
MATLAB modeling this can be seen from the plot in the Figure 4.16. For Binary Phase
Shift Keying (BPSK) the shift is 180 degrees and for Quadrature Phase Shift Keying
(QPSK) the phase shift is 90 degrees. Hint that applying QPSK over BPSK enables either
higher data rates or lower bandwidth depending on the requirement.
1
Amplitude
-1
0 1 2 3 4 5 6 7 8
Time (bit period)
Original Digital Signal
1.5
1
Amplitude
0.5
-0.5
0 1 2 3 4 5 6 7 8
Time (bit period)
Frequency Shift Keying (FSK) demonstrates the digital data in the form of variation of
the frequency of a carrier wave. For Binary Shift Keying (BPSK), a logical 0 is represented
by one frequency and a logical 1 is represented by a different frequency. As a result of
MATLAB modeling this can be seen from the plot in the Figure 4.17.
1
Amplitude
-1
0 1 2 3 4 5 6 7 8
Time (bit period)
Original Digital Signal
1.5
1
Amplitude
0.5
-0.5
0 1 2 3 4 5 6 7 8
Time (bit period)
5. NFC APPLICATIONS
Near Field Communication (NFC) is a technology for contactless wireless short range
communication where the technology is extended over existing Radio Frequency
Identification (RFID) technology. NFC establishes communication link by generating
magnetic field induction.
There is wide range of short range applications for NFC and still these applications are
growing rapidly in a way that it is impossible to give a complete picture of them. These
applications can be defined for mobile and portable devices, PC world and consumer
application (Philips 2011), Figure 5.1 shows an idea of NFC application. But especially the
use of NFC chips with mobile phones prepares wide and many opportunities by integrating
it into mobile devices which this provides a high advantage and functionality.
62
NFC has three operating modes which they are; Reader and Writer, Card Emulation and
Peer to Peer communication. Any application provided by NFC chip requires applying one
the mentioned operating modes for the short range communication (Ok, Aydin, Cosckun &
Ozdenizci 2011). In addition each of these modes provides some functionality for the NFC
integrated device. Here the concepts of these three different modes are reviewed.
Reader and Writer mode means that this mode enables the device to read and write
the data from or to the NFC compatible tags (NFC Specifications).
Card Emulation mode is that the device acts as an emulated card and external NFC
readers read the data that resides in NFC enabled device (NFC Specifications).
Peer to Peer mode is that two devices can exchange the data at the link level where
this mode is standardized on ISO/IEC 18092 standard which allows the data speed
up to 424 kbps (NFC Specifications).
Also since NFC technology and the protocol, standard, prototype and applications are
developed by the academic and industry units. The amounts of NFC applications have been
increased rapidly in recent years. Based on the desired application and the related data
model in each application one of the mentioned operating modes is used and using each of
these modes specifies that how NFC equipped devices communicate with one another (Ok
et al. 2011)
As it is said the applications provided by the new short range NFC technology is rapidly
increased to catch a glimpse on some of the existing application, here it is good to mention
to some of them where this gives a better sight of understanding this technology in real life.
63
Identification
Instead of using ID Cards or documents such as passports, NFC gives the
possibility of using mobile phones for person’s identification. As an example, in
Japan, students Identification Cards can be stored on their cell phones. This allows
the students to register to the courses using this technology or even they can open
the locked campus doors, buy food from the school canteen, borrow books from the
library and totally where ever the student ID is required, they can use their mobile
phones.
Set Up Service
One of the applications of NFC is to set up the other longer wireless technologies
such as Bluetooth or Wireless LAN due to initiating and configuring connection
between two NFC enabled devices by bringing them together to activate the NFC
connection. Also once the configuration is completed, the devices can be separated
for longer range communication.
Electronic keys
The technology makes it possible to use NFC instead of Electronic keys such as
office, house or car keys.
64
In addition there are so many other applications are developed such as, lock on personal
computers, vending Machines, parking meters, applications used for ATMs and many
others, Figure 5.2 represents some of these applications. The technology is so new that it is
still possible to define new applications for different purposes.
6. NFC SECURITY
One of the most important and considerable aspects of Near Field Communication is the
security issue. However this type of short range wireless communication which is limited to
few centimeters and the technology is user aware interaction but still this awareness does
not guarantee a safe and secure communication, because there may be are different types of
threads toward NFC communication. One of the major threads is that the communicator
device has been manipulated physically where this can be done in different ways as
follows;
Another considerable thread can be caused by the type of tag which is used in the tagged
device, in case, if the tag is readable or writable. The type of tag specifies authorized or
unauthorized user accessed to the information stored in the tag because read only tags are
safe and secure against unauthorized write access. Furthermore in case of rewritable tags, it
should be assumed that the attacker has a reader device and the required software which
enables unauthorized read and write access (Oertel, Köhler, Wittmann 2005).
Meanwhile for error checking, NFC applies cyclic redundancy check (CRC). This error
checking method allows communicating devices to check to see if the received data has
been corrupted or not.
66
Also addition to the mentioned threads above, there are some major NFC security areas
need to be discussed, these areas are listed below:
Eavesdropping
Data corruption
Data modification
Data Insertion
Man in middle attack
Where in the rest of this chapter these thread areas and the solutions and recommendations
will be discussed.
6.1 Eavesdropping
Eavesdropping is one of the major attacks is done in all wireless communication as well as
NFC. As it is discussed in previous chapters the communication by NFC is done based on
generation of RF waves. Definitely any attacker can use an antenna in order to receive the
transmitted signals and by using required equipment and the knowledge of extracting the
received signals, will be able to decode the data.
The distance for the communication between NFC devices is limited in which this distance
is not more than 10 centimeters and practically it is done by 4 cm. Therefore this question
comes to the mind that how an eavesdropper needs to be close to this range to be able to
receive the ongoing signals? The answer is that, unfortunately there is no any correct
answer for this question, because the answer depends on the huge number of parameters
which involve NFC communication. Some of these parameters are:
RF field characteristics of the given sender device such as the antenna geometry,
shielding effect of the case, PCB, environment and etc.
Characteristics of the attacker’s antenna such as again antenna geometry and the
possibility to change the position in all three dimensions.
67
Eavesdropping shall not be the only purpose of the attacker, attacker may try to destruct,
corrupt or modify the data which is transmitted via the NFC interface. In the first step the
attacker may try to disturb the communicators in a way to cut the link and then the result
would be the service is no more available. This can be done by achieving the transmitted
frequencies of the data spectrum at a correct time, where this time can be estimate and
calculated if the attacker has a good understanding of the applied modulation technique and
coding method and using a jammer. This type of attacking is not that complicated but still
the attacker is not to manipulate the data and it is simply a Denial of Service attack.
68
This type of attack cannot be prevented but it is possible to detect because of the jamming
power needed to corrupt the data is bigger than transmitting power is used by the
communicator. NFC devices are able to receive and transmit the data at the same time
where this feature is the reason for jammer signal detection because the device can check
the incoming signals and notice the collision. In addition in order to preventing the
jamming signal Spread Spectrum can be applied and studied in data transmission, where
spread spectrum is a digital modulation technology and a technique based on principle of
spreading a signal among many frequencies to prevent interference and signal interception.
Also as the name implies it is a method of spreading the transmitted spectrum over a wide
range of frequencies. For the first time it started to be employed by military applications
because of its Low Probability of Intercept (LPI) or demodulation, interference and anti-
jamming from the enemy side. The idea of spreading spectrum it to spread a signal over a
large frequency band to use a greater bandwidth than the data bandwidth while the power
remains the same. And as far as the spread signal looks like the noise signal in the same
frequency band it is difficult to recognize the signal which this feature of spreading
provides security to the transmission (Hossein Motlagh 2010).
Unlike the data destruction and corruption, sometimes the attacker wants to manipulate the
data and modifies it as he desires. This intention requires accessing the strength of the
amplitude modulation and the reason for this is that the decoding of the signal for 10% and
100% modulations as discussed in chapter 4 are different in order to change the value of bit
from 0 to 1 or vice versa.
In 100% modulation the decoder checks the two half bits for the RF signal to see if it is
paused meaning off and not paused which means on. Attacker, due to understanding the
value of the bit (1 or 0) has to do two main things:
69
1. A pause must be filled up in the modulation with the carrier frequency where this is
feasible.
2. A pause of RF signal must be generated which is received by a proper receiver.
For the second case, the attacker has to transmit some RF signal where these signals
should overlap with the original ones at the receiver’s antenna to input a zero signal at
the receiver, but this is not feasible in practice. Though, because of subsequent ones
generated by Modified Miller coding, the attacker can change the value of second bit
from one to zero, by filling the pause which encodes the second bit value. Therefore,
the decoder does not see a pause in the second bit and would decode it as a correct zero
wrongly, because it is preceded by a one.
So, in 100% modulation, the attacker can never change a bit of value 0 to a bit of value
1, however the attacker can change a bit of value 1 to a bit of value 0, on a condition
that this bit is precede by a bit of value one. This is shown in Figure 6.1.
What an attackers does is, adds a signal to the 82% such that this signals appears as a full
signal and the actual full signal becomes an 82% signal. Using this attacking method if the
real bit value is zero will be decoded as one and other way around. Therefore the attack is
feasible for all bits on 10% ASK with Manchester coding but for 100% it is feasible only
for some certain bits.
But the solution for the data modification can be obtained by different ways. First way is
applying 106kBaud in active mode, doing this makes it impossible for an attacker to
modify all the data (Haselsteiner & Klemens 2006). While this means that both of the
communicating devices need to be in active mode but the disadvantage of using active
modes in both sides eases the eavesdropping. Also this is not a fully prevention of the data
modification because still some bits can be modified. The other solution can be checking
RF field continuously while communicating and with this if there is any threat detected the
communication can be stopped. Addition to all these the best solution should be
transmitting the data over a safe and secure channel as mentioned formerly.
This type of thread means that the attacker inserts intended data into the ongoing actual
information between the communication parties. But the message traveling time has the
important role for enabling the attacker to insert the intended data into it. Then the
attacker’s insertion will be successful only if the answering device requires a very long time
to answer. Also in case of collision, the message would be corrupted and the data exchange
would be stopped. There are three possible solutions for this, first is that the answering
device should answer without any delay time so the attacker cannot be faster than the
answering device and as it is said the collision leads to corruption of the received signals.
Second way is the receiving device should listing to the medium while transmission so this
will help to detect the attacker. In addition or overcome to this problem it is always goof to
use a safe and secure channel.
71
Man in the Middle Attack is a form of a thread that the communication parties are not
aware that they are not communicating to each other, but they are both sending and
receiving data from Eve, the idea shown in Figure 6.2. To distinguish this type of thread,
the active and passive modes must be considered. Assuming that in a passive mode the
active device A generates the RF field for sending to a passive device B. Meanwhile the
attacker tries to prevent device B from receiving the data where this is possible but still this
can be detected if device A check the medium while transmitting.
On the next step the attacker may desire to change and replace the actual data where this is
not feasible because the attacker must generate its own RF field and this must be aligned
with the RF field of the sender A.
Device A Device B
Eve
Compared to the passive mode, the active mode device A switches off the RF field. Now
eve turns on the RF field and can send the data and but the problem is that device A is
listening to the channel and waiting for the answer from device B. Then the device A
instead of receiving the data from device B, receives it from the Eve. The solution to
overcome to this type of thread is that to apply active-passive communication mode in a
way that FR field is generated continuously by a valid communicating party. Addition to
this the task of the active party should be listening to RF field while transferring the data
due to finding and disturbance caused by a Man in the Middle Attacker.
72
Along with standard key agreement mechanism in NFC protocol, there is a possibility to
implement an NFC specific key agreement where this agreement the computational
requirement and theoretically increases the communication security. This specific key
agreement is not part of ISO standard and it just works with 100% ASK modulation.
In this scheme both of the NFC communicating devices calling them device A and B, they
send random data at the same time. Also as the devices can communicate at the same time,
in the set up phase both of the devices synchronize on the exact timing of the bits and also
on the amplitude and the phase of RF signal. Then after the devices are synchronized, both
of them will be able to transmit at the same time with exactly the same amplitude and
phases (Haselsteiner & Klemens 2006).
Furthermore during sending random bits of 0 or 1, each single device listens to the RF
field. The scheme is so that if the devices send a zero, the sum of the signals will become
zero and if both of them send 1’s then the sum of the signals will be the double RF signal.
Therefore the attacker will be aware that both of the devices send 0 or 1, where this is not
helping at all. But for example if device A sends a zero signal and device B sends 1 or other
way around and always summing them is 1 and this will be difficult for the attacker to
figure out which one has sent 0 or 1. Besides the devices they know that what has the other
party has sent and this is because each of the devices knows that what it has sent so. This
idea is shown by Figure 6.x which is a MATLAB plot. The plot shows two signals
generated by A in red color and B in blue. The two parties they send following eight bits,
bit_stream1 for signal A and bit_stream2 for signal B.
bit_stream1 = [0 1 0 1 1 0 1 0];
bit_stream2 = [0 1 1 0 0 1 1 0];
73
And the lower graph which is the resulting signal by summing of signals A and B, shown
by blue where this is the signal can be seen by the attacker. Clearly the resulting signal
where A sends a bit 0 or 1, or B sends the opposite bit for the attacker is the same and not
distinguishable.
1
Amplitude
-1
-2
-3
0 1 2 3 4 5 6 7 8
Time (bit period)
NFC Specific Key Agreement
3
2
1
Amplitude
-1
-2
-3
0 1 2 3 4 5 6 7 8
Time (bit period)
Also whenever both of the devices send the same bits, then they discard them and when the
devices send the different bits, they collect the bits for later use. Besides this must be
agreed on startup and applying this way devices A and B can agree on an arbitrary long
shared secret where the generation of a 128 bit shared secret would need approximately 256
bits to be transmitted. At a baud rate of 106 kBaud this takes about 2.4 ms and this is fast
enough for all applications. Furthermore, in actual case the security of this protocol
depends on the quality of synchronization which is achieved between two devices. Also if
74
the received signal by the eavesdropper is below noise level the protocol is secure, then one
can say that the level of security is dependent on the signal quality at the receiver side
(Haselsteiner & Klemens 2006).
75
NFC is a new technology developed over RFID, in a way that it consists of an interface and
protocol are based on RFID which makes NFC device to a part of this standard and
compatible with existing RFID technology. It enables a contactless, wireless
communication between portable devices close to each other less than 4 centimeters or
touching them physically. NFC supports data rate of 106 kbps for the minimum and 212
kbps and 424kbps at the maximum. It provides easy connections, quick transactions, and
simple data sharing. The main technical feature of NFC is that it complements many
existing wireless technologies by utilizes the key parameters and elements in the existing
standards for contactless card technology. NFC applies electromagnetism physics and
principles for communication establishment. The modulation of the electromagnetic waves
can be done through different techniques which they are ASK, FSK and PSK. There is wide
range of short range applications for NFC and still these applications are growing rapidly in
a way that it is impossible to give a complete picture of them. These applications can be
defined for mobile and portable devices, PC world and consumer application. But
especially the use of NFC chips with mobile phones provides many opportunities and
advantages. Furthermore one of the most important and considerable aspects of NFC is the
security issue. As far as the higher the importance of the data to be sent or shared, the
concept of the security becomes more and more important where there have been many
threads toward this type of communication is considered and discussed.
As the future work, it seems that in many applications of NFC, the ASK modulation
technique is applied. Therefore this could be suggested that by using MATLAB, the other
techniques can be applied in the model of NFC in order to compare the efficiency and the
performance of different modulation techniques, also the effect of noise and interference
could be considered and studied.
76
In addition as the use of NFC is increasing, this may be useful to define for many
applications. So it is possible to think on and developing new application that still does not
exist. Beside as the applications are growing then security issue comes to importance first
and still there could be new techniques to be defined in order to accessing the attackers to
the ongoing information between communicating parties.
77
REFERENCES
Atmel (2010). Considerations for RFID Technology Selection [online] [cited 12 Feb.
2012]. Available from the Internet <URL: [Link]
Considerations-for-RFID-Technology-Selection>
Balanis, Constantine A. (2005). Antenna Theory: Analysis and Design. John Wiley and
Sons, Inc. 1136 p. ISBN: 978-0-471-66782-7.
Ecma International (2004). Near Field Communication Interface and Protocol (NFCIP-1).
[online] [cited 8 May. 2012]. Available from the Internet <URL: [Link]
[Link]/publications/standards/[Link]>
ETSI (2003). Near Field Communication (NFC)IP-1 : Interface and Protocol (NFCIP-1).
[online] [cited 8 May. 2012]. Available from the Internet <URL:
[Link]
[Link]>
Fischer, Jeffrey (2009). The New Paradigm for an Interactive World. Communications
Magazine, IEEE. 22-28. ISSN: 0163-6804.
Haselsteiner, Ernst & Breitfuss, Klemens (2006). Security in near field communication
(NFC). [online] [cited 8 May. 2012]. Available from the Internet <URL:
[Link]
in%[Link]>
Hioki, Warren (2000). Telecommunications. 4th Ed. New Jersey, USA: Prentice Hall. 664 p.
ISBN: 013020031X.
78
NFC Forum. NFC and Contactless Technologies [online] [cited 27 Feb. 2012]. Available
from the Internet <URL: [Link]
NFC Forum. NFC Forum Technical Specifications [online] [cited 25 Feb. 2012]. Available
from the Internet <URL: [Link]
Oertel, Wölk, Köhler, Kelter, Wittmann, Ullmann (2005). Security Aspects and Prospective
Applications of RFID Systems. [online] [cited 8 May. 2012]. Available from the
Internet <URL: [Link]
Ok, Kerem, Mehmet, N. Aydin, Vedat Coskun, and Busra Ozdenizci (2011). Exploring
Underlying Values of NFC Applications. Singapore : 3rd International Conference on
Information and Financial Engineering. Department of Information Technologies,
ISIK University, Istanbul, Turkey (Ok et al. 2011).
Omni-ID. Omni-ID RFID products [online] [cited 25 Feb. 2012]. Available from the
Internet <URL:[Link]
_Guide.pdf>
Paus , Annika (2007). Near Field Communication in CellPhones. [online] [cited 8 May.
2012]. Available from the Internet <URL: [Link]
[Link]/media/crypto/attachments/files/2011/04/near_field_communication_in_ce
ll_phones.pdf>
79
Philips Semiconductors (2011). PN532/C1 NFC Controller. [online] [cited 8 May. 2012].
Available from the Internet <URL: [Link]
.25p. Short Form Datasheet.
RFID Journal (2002). A Summary of RFID Standards. [online] [cited 8 May. 2012].
Available from the Internet <URL: [Link]
Whithfield, Diffie & Martin, Hellman (1976). New directions in cryptography [online]
[cited 5 May. 2012]. Available from the Internet <URL:[Link]
~hellman/publications/[Link]>. IEEE Transactions on Information Theory 22.
80
APPENDICES
ASK_signal = [];
Digital_signal = [];
for ii = 1: 1: length(bit_stream)
% The FSK Signal
ASK_signal = [ASK_signal (bit_stream(ii)==0)*A1*sin(2*pi*f*t)+...
(bit_stream(ii)==1)*A2*sin(2*pi*f*t)];
81
format long;
PSK_signal = [];
Digital_signal = [];
for ii = 1: 1: length(bit_stream)
% The FSK Signal
PSK_signal = [PSK_signal (bit_stream(ii)==0)*sin(2*pi*f*t + P1)+...
(bit_stream(ii)==1)*sin(2*pi*f*t + P2)];
83
format long;
for ii = 1: 1: length(bit_stream)
signal = [];
Digital_signal1 = [];
Digital_signal2 = [];
for ii = 1: 1: length(bit_stream1)
% The Original Digital Signal
Digital_signal1 = [Digital_signal1 (bit_stream1(ii)==0)*...
zeros(1,length(t)) + (bit_stream1(ii)==1)*ones(1,length(t))];
Digital_signal2 = [Digital_signal2 (bit_stream2(ii)==0)*...
zeros(1,length(t)) + (bit_stream2(ii)==1)*ones(1,length(t))];
RFID coupling methods—backscatter, capacitive, and inductive—significantly impact communication distance and frequency. Backscatter coupling is suitable for long-range RFID communication, operating over distances between 1 and 10 meters using higher frequencies. Capacitive and inductive coupling are more suitable for short-range communications; capacitive uses electric fields while inductive employs magnetic fields, typically within 1 meter. These methods generally operate at lower frequencies .
Active RFID tags have an internal power source such as a battery, allowing them to provide signals over extended ranges of up to 100 meters, making them more expensive and larger in size. Passive RFID tags rely on the RFID reader for power, meaning they can only be read within a few meters and are cheaper and smaller in size .
Short-wavelength inductive coupling in RFID systems implies a limited communication range due to the near-field nature of inductive coupling, often requiring close proximity between the reader and the tag, usually less than 0.15 wavelengths. This range limits its applicability to environments where such short distances are permissible and beneficial, such as high-security zones or tightly controlled areas. It ensures effective energy transfer and data modulation, often beneficial where minimal interference is critical .
In active communications, continuous monitoring of the RF field while transferring data helps detect disruptions caused by a man-in-the-middle attacker. The use of active-passive mode, where the RF field is continuously generated by a legitimate party, enhances security. Applying secure channels and immediate response times also help mitigate such threats. In passive mode, the attacker must balance their own RF field with the sender's, which is difficult to achieve without detection .
Close-range coupling in RFID systems offers benefits such as high-security communication and efficient energy absorption by the tag because of the proximity to the reader. Inductive and capacitive methods are commonly used for such close-range communications due to their effectiveness in transmitting signals over very short distances, typically up to 1 centimeter .
RFID inductive coupling operates by utilizing mutual inductance between the coils of the reader and the tag. When a tag is close to the reader, the magnetic field generated by the reader induces a voltage in the tag's coil, providing power for its operation. This method is a near-field technique, requiring the distance between the coils to be within 0.15 of the wavelength of the frequency used, which is typically below 135 kHz, allowing effective power transfer and communication over short distances .
In NFC active mode communication, both devices generate their own RF fields alternately while communicating, requiring collision management to avoid interference. Initiators must detect any existing RF fields before starting communication. Passive mode communication involves only the initiator generating the RF field, with the target using load modulation to respond. Collision management in this mode is managed by the initiator listening for simultaneous responses, which are then disregarded to prevent errors, ensuring seamless single device detection and general initialization .
The internal electronic circuitry of RFID tags and readers is crucial for communication efficiency and security. Efficient designs, featuring resonant circuits and properly matched antenna components, ensure precise power transfer and data modulation, enhancing signal clarity and range. Security is reinforced through secure electronic components that safeguard against signal interference and eavesdropping. The choice of components and the quality of design directly affect the system's vulnerability to errors and malicious attacks .
Choosing between passive and semi-passive RFID tags involves considering trade-offs in power source, range, and cost. Passive tags, relying on external energy from the reader, are cheaper and smaller but have limited read ranges and storage capacity. Semi-passive tags alleviate this by using an internal battery for the tag's internal operations, offering better data storage and moderate range, though they still depend on the reader for transmitting data. However, they are more expensive and larger than passive tags, making the decision application-dependent .
Manchester coding is used in NFC data transmission by ensuring transitions in the middle of each bit period, with a low to high transition representing a '0' and a high to low indicating a '1,' thus facilitating synchronization. Modified Miller coding, on the other hand, represents bits by the presence or absence of pulses within specific timeframes of the bit period, providing alternative advantages in signal clarity and timing precision. These coding methods help maintain accuracy and integrity during NFC data communications .