A Secure and Authenticated Mobile Payment Protocol Against Off-Site Attack Strategy

被引:13
作者
Fang, Liming [1 ]
Li, Minghui [1 ]
Liu, Zhe [1 ]
Lin, Changting [2 ]
Ji, Shouling [3 ]
Zhou, Anni [4 ]
Susilo, Willy [5 ]
Ge, Chunpeng [1 ]
机构
[1] Nanjing Univ Aeronaut & Astronaut, Coll Comp Sci & Technol, Nanjing 210016, Jiangsu, Peoples R China
[2] Zhejiang Univ, Binjiang Inst, Hangzhou 310027, Zhejiang, Peoples R China
[3] Zhejiang Univ, Coll Comp Sci & Technol, Hangzhou 310027, Peoples R China
[4] Georgia Inst Technol, Atlanta, GA 30332 USA
[5] Univ Wollongong, Inst Cybersecur & Cryptol, Wollongong, NSW 2522, Australia
基金
国家重点研发计划; 中国国家自然科学基金;
关键词
Security; Servers; Online banking; Resists; Protocols; Hardware; Germanium; Internet of things (IoT); mobile payment security; payment token; off-site attack; IDENTITY-BASED SIGNATURE;
D O I
10.1109/TDSC.2021.3102099
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Mobile payment system has been expected to provide more efficient and convenient payment methods. However, compared to traditional payments, mobile payment issues related to the security of electronic accounts and payment apps present serious challenges. In this paper, we find the potential security risks by analyzing the commonly used tokenized mobile payment method and put forward the corresponding off-site attack strategy. In this scenario, the attackers are not only limited to malicious third parties but also can be illegal merchants. To address the off-site attack, especially the potential attackers who may be malicious merchants, we also propose SALP, a secure and authenticated payment protocol, using time and position as necessary conditions for the payment confirmation. Furthermore, we leverage identity-based signature (IBS) to prevent altering the information and reduce the overhead of the third-party authentication. We conduct case studies to demonstrate that the SALP can effectively prevent the off-site payment attack without a trusted hardware environment. In particular, we finally argue that SALP does not bring additional system overhead without degrading the convenience of mobile payment.
引用
收藏
页码:3564 / 3578
页数:15
相关论文
共 34 条
[1]   QuickCash: Secure Transfer Payment Systems [J].
Alhothaily, Abdulrahman ;
Alrawais, Arwa ;
Song, Tianyi ;
Lin, Bin ;
Cheng, Xiuzhen .
SENSORS, 2017, 17 (06)
[2]  
[Anonymous], GSMA STATE IND REPOR
[3]  
[Anonymous], NETEASE NEWS BE CARE
[4]  
Bai XL, 2017, PROCEEDINGS OF THE 26TH USENIX SECURITY SYMPOSIUM (USENIX SECURITY '17), P593
[5]   Identity-based encryption from the Weil pairing [J].
Boneh, D ;
Franklin, M .
SIAM JOURNAL ON COMPUTING, 2003, 32 (03) :586-615
[6]  
Buchholz D. B., 2001, US Patent, Patent No. 6198750
[7]  
Cha JC, 2003, LECT NOTES COMPUT SC, V2567, P18
[8]   A Secure Video-Based Robust and Aesthetic 2D Barcode [J].
Chen, Changsheng ;
Lan, Fengbo ;
Mow, Wai Ho .
INTERNET AND DISTRIBUTED COMPUTING SYSTEMS, 2018, 11226 :282-287
[9]  
Choi D., 2016, PROC WORKSHOP OFFENS, P1
[10]  
Choi Jun-won, 2018, U.S. Patent, Patent No. [9,990,622, 9990622]