PSP: Private and secure payment with RFID

被引:4
作者
Blass, Erik-Oliver [1 ,3 ]
Kurmus, Anil [2 ]
Molva, Refik [3 ]
Strufe, Thorsten [4 ]
机构
[1] Northeastern Univ, Coll Comp & Informat Sci, Boston, MA 02115 USA
[2] IBM Res Zurich, CH-8803 Ruschlikon, Switzerland
[3] EURECOM, F-06410 Biot, France
[4] Tech Univ Darmstadt, D-64289 Darmstadt, Germany
关键词
RFID; Payment; Privacy; Security; Ecash; ATTACKS;
D O I
10.1016/j.comcom.2012.10.012
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
RFID can be used for a variety of applications, e.g., to conveniently pay for public transportation. However, achieving security and privacy of payment is challenging due to the extreme resource restrictions of RFID tags. In this paper, we propose PSP - a secure, RFID-based protocol for privacy-preserving payment that supports multiple different payees. Similar to traditional electronic cash, the user of a tag can pay for a service using his tag and so called coins of a virtual currency. With PSP, tags do not need to store valid coins, but generate them on the fly. Using Bloom filters, readers can verify the validity of generated coins offline. PSP guarantees privacy such that neither payees nor an adversary can reveal the identity of a user or link subsequent payments. PSP is secure against invention and overspending of coins, and can reveal the identity of users trying to double spend coins. Still, PSP is lightweight: it requires only a hash function and few bytes of non-volatile memory on the tag. (c) 2012 Elsevier B.V. All rights reserved.
引用
收藏
页码:468 / 480
页数:13
相关论文
共 43 条
[1]  
Amazon, 2009, WEBS SIMPL MONTHL CA
[2]  
[Anonymous], 2002, LNCS, DOI DOI 10.1007/3-540-45760-7_11
[3]  
[Anonymous], 2006, GUARDIAN
[4]  
[Anonymous], 2005, INFORMATIONWEEK
[5]  
[Anonymous], 1994, Advances in Cryptology-CRYPTO' 93, DOI DOI 10.1007/3-540-48329-2_26
[6]  
Avoine G, 2006, LECT NOTES COMPUT SC, V3897, P291
[7]  
Bellare M., 2006, ANN INT CRYPT C SANT
[8]  
Bellare M., 1996, ANN INT CRYPT C SANT
[9]  
Blass E.-O., 2009, 8 ACM WORKSH PRIV EL
[10]   The Ff-Family of Protocols for RFID-Privacy and Authentication [J].
Blass, Erik-Oliver ;
Kurmus, Anil ;
Molva, Refik ;
Noubir, Guevara ;
Shikfa, Abdullatif .
IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2011, 8 (03) :466-480