Enhancing EMV Tokenisation with Dynamic Transaction Tokens

被引:1
作者
Jayasinghe, Danushka [1 ]
Markantonakis, Konstantinos [1 ]
Akram, Raja Naeem [1 ]
Mayes, Keith [1 ]
机构
[1] Royal Holloway Univ London, Informat Secur Grp, Smart Card Ctr, Egham TW20 0EX, Surrey, England
来源
RADIO FREQUENCY IDENTIFICATION AND IOT SECURITY | 2017年 / 10155卷
关键词
Tokenisation; Security; Dynamic transaction token; EMV; contactless mobile payments; Cryptography; Scyther; Formal analysis; SECURITY PROTOCOLS;
D O I
10.1007/978-3-319-62024-4_8
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Europay MasterCard Visa (EMV) Tokenisation specification details how the risk involved in Personal Account Number (PAN) compromise can be prevented by using tokenisation. In this paper, we identify two main potential problem areas that raise concerns about the security of tokenised EMV contactless mobile payments, especially when the same token also called a static token is used to pay for all transactions. We then discuss five associated attack scenarios that would let an adversary compromise payment transactions. It is paramount to address these security concerns to secure tokenised payments, which is the main focus of the paper. We propose a solution that would enhance the security of this process when a smart phone is used to make a tokenised contactless payment. In our design, instead of using a static token in every transaction, a new dynamic token and a token cryptogram is used. The solution is then analysed against security and protocol objectives. Finally the proposed protocol was subjected to mechanical formal analysis using Scyther which did not find any feasible attacks within the bounded state space.
引用
收藏
页码:107 / 122
页数:16
相关论文
共 24 条
[1]  
[Anonymous], 2015, APPLE PAY JUL
[2]  
[Anonymous], 2016, THEHACKERNEWS
[3]  
[Anonymous], 2015, BBC NEWS
[4]  
[Anonymous], 2015, EMV CONT SPEC PAYM S
[5]  
[Anonymous], 2016, ANDROID PAY JUN
[6]  
Askoxylakis I. G., 2007, SYSTEM, V12, P13
[7]   Be Prepared: The EMV Preplay Attack [J].
Bond, Mike ;
Choudary, Marios O. ;
Murdoch, Steven J. ;
Skorobogatov, Sergei ;
Anderson, Ross .
IEEE SECURITY & PRIVACY, 2015, 13 (02) :56-64
[8]   Chip and Skim: cloning EMV cards with the pre-play attack [J].
Bond, Mike ;
Choudary, Omar ;
Murdoch, Steven J. ;
Skorobogatov, Sergei ;
Anderson, Ross .
2014 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2014), 2014, :49-64
[9]   Relay Cost Bounding for Contactless EMV Payments [J].
Chothia, Tom ;
Garcia, Flavio D. ;
de Ruiter, Joeri ;
van den Breekel, Jordi ;
Thompson, Matthew .
FINANCIAL CRYPTOGRAPHY AND DATA SECURITY (FC 2015), 2015, 8975 :189-206
[10]  
Computerworld.com, 2012, VULN FOUND 3 POP PAY