13 Steps to Improve Security and Privacy when Developing a Smart Lock

백서

Our team recently analyzed the security of three popular smart locks: those that typically provide extra functionality like remote unlock, smartphone integration, advanced authentication methods, etc. On all devices, we analyzed the internals, reverse engineered the firmware and corresponding smartphone applications, and tried several attacks to see if the locks could be compromised. In summary:

  • The first lock could be opened using a physical attack on the external unit. We estimate that, with some practice, this lock can be compromised within a few minutes.
  • The second lock could be opened using a cryptographic attack on the wireless communication protocol, allowing the door to be remotely opened within one hour and without physical access to the lock/door.
  • The third lock was sufficiently protected to resist our attacks. However, we did find that this lock is vulnerable to a denial-of-service attack, preventing legitimate users from unlatching the lock. We also found a privacy issue described later in this document.

 

These findings show that smart locks can introduce new risks and that there should be more emphasis on security in the development process. Based on our analysis, combined with our extensive experience in evaluating secure embedded devices, we provide 13 recommendations for smart lock developers.