Security and Privacy Implications of NFC-enabled Contactless Payment Systems

被引:17
作者
Akinyokun, Nicholas [1 ]
Teague, Vanessa [1 ]
机构
[1] Univ Melbourne, Sch Comp & Informat Syst, Melbourne, Vic, Australia
来源
PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2017) | 2017年
关键词
Near Field Communication; NFC technology; contactless payments; mobile payments; mobile wallets; ATTACKS;
D O I
10.1145/3098954.3103161
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Nowadays, contactless payments are becoming increasingly common as new smartphones, tablets, point-of-sale (POS) terminals and payment cards (often termed "tap-and-pay" cards) are designed to support Near Field Communication (NFC) technology. However, as NFC technology becomes pervasive, there have been concerns about how well NFC-enabled contactless payment systems protect individuals and organizations from emerging security and privacy threats. In this paper, we examine the security of contactless payment systems by considering the privacy threats and the different adversarial attacks that these systems must defend against. We focus our analysis on the underlying trust assumptions, security measures and technologies that form the basis on which contactless payment cards and NFC-enabled mobile wallets exchange sensitive transaction data with contactless POS terminals. We also explore the EMV and ISO standards for contactless payments and disclose their shortcomings with regards to enforcing security and privacy in contactless payment transactions. Our findings shed light on the discrepancies between the EMV and ISO standards, as well as how card issuing banks and mobile wallet providers configure their contactless payment cards and NFC-enabled mobile wallets based on these standards, respectively. These inconsistencies are disconcerting as they can be exploited by an adversary to compromise the integrity of contactless payment transactions.
引用
收藏
页数:10
相关论文
共 61 条
[1]  
Alzahrani A, 2013, IEEE PAC RIM CONF CO, P302, DOI 10.1109/PACRIM.2013.6625493
[2]  
American Express, 2017, AM EXPR EXPRESSRAY
[3]  
[Anonymous], 2004, ISOIEC18092
[4]  
[Anonymous], P 6 INT C RAD FREQ
[5]  
[Anonymous], 2005, ISOIEC21481
[6]  
[Anonymous], 2013, ISOIEC7816
[7]  
[Anonymous], 2016, ISOIEC144432
[8]  
Apple Inc, 2017, APPL PAY
[9]   An NFC Relay Attack with Off-the-shelf Hardware and Software [J].
Bocek, Thomas ;
Killer, Christian ;
Tsiaras, Christos ;
Stiller, Burkhard .
MANAGEMENT AND SECURITY IN THE AGE OF HYPERCONNECTIVITY, AIMS 2016, 2016, 9701 :71-83
[10]   Be Prepared: The EMV Preplay Attack [J].
Bond, Mike ;
Choudary, Marios O. ;
Murdoch, Steven J. ;
Skorobogatov, Sergei ;
Anderson, Ross .
IEEE SECURITY & PRIVACY, 2015, 13 (02) :56-64