Evaluation of Apple iDevice Sensors as a Potential Relay Attack Countermeasure for Apple Pay

Gareth Haken, K. Markantonakis, Iakovos Gurulian, Carlton Shepherd, Raja Naeem Akram
{"title":"Evaluation of Apple iDevice Sensors as a Potential Relay Attack Countermeasure for Apple Pay","authors":"Gareth Haken, K. Markantonakis, Iakovos Gurulian, Carlton Shepherd, Raja Naeem Akram","doi":"10.1145/3055186.3055201","DOIUrl":null,"url":null,"abstract":"Traditional countermeasures to relay attacks are difficult to implement on mobile devices due to hardware limitations. Establishing proximity of a payment device and terminal is the central notion of most relay attack countermeasures, and mobile devices offer new and exciting possibilities in this area of research. One such possibility is the use of on-board sensors to measure ambient data at both the payment device and terminal, with a comparison made to ascertain whether the device and terminal are in close proximity. This project focuses on the iPhone, specifically the iPhone 6S, and the potential use of its sensors to both establish proximity to a payment terminal and protect Apple Pay against relay attacks. The iPhone contains 12 sensors in total, but constraints introduced by payment schemes mean only 5 were deemed suitable to be used for this study. A series of mock transactions and relay attack attempts are enacted using an iOS application written specifically for this study. Sensor data is recorded, and then analysed to ascertain its accuracy and suitability for both proximity detection and relay attack countermeasures.","PeriodicalId":140504,"journal":{"name":"Proceedings of the 3rd ACM Workshop on Cyber-Physical System Security","volume":"62 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-04-02","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 3rd ACM Workshop on Cyber-Physical System Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3055186.3055201","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5

Abstract

Traditional countermeasures to relay attacks are difficult to implement on mobile devices due to hardware limitations. Establishing proximity of a payment device and terminal is the central notion of most relay attack countermeasures, and mobile devices offer new and exciting possibilities in this area of research. One such possibility is the use of on-board sensors to measure ambient data at both the payment device and terminal, with a comparison made to ascertain whether the device and terminal are in close proximity. This project focuses on the iPhone, specifically the iPhone 6S, and the potential use of its sensors to both establish proximity to a payment terminal and protect Apple Pay against relay attacks. The iPhone contains 12 sensors in total, but constraints introduced by payment schemes mean only 5 were deemed suitable to be used for this study. A series of mock transactions and relay attack attempts are enacted using an iOS application written specifically for this study. Sensor data is recorded, and then analysed to ascertain its accuracy and suitability for both proximity detection and relay attack countermeasures.
Apple device传感器作为Apple Pay潜在中继攻击对策的评估
由于硬件的限制,传统的中继攻击对策难以在移动设备上实现。建立支付设备和终端的接近性是大多数中继攻击对策的中心概念,移动设备在这一研究领域提供了新的和令人兴奋的可能性。其中一种可能性是使用车载传感器来测量支付设备和终端的环境数据,通过比较来确定设备和终端是否距离很近。这个项目的重点是iPhone,特别是iPhone 6S,以及它的传感器的潜在用途,既可以建立接近支付终端,又可以保护Apple Pay免受中继攻击。iPhone总共包含12个传感器,但由于支付方案的限制,只有5个被认为适合用于这项研究。使用专门为本研究编写的iOS应用程序实施了一系列模拟交易和中继攻击尝试。对传感器数据进行记录,然后进行分析,以确定其在接近检测和中继攻击对策中的准确性和适用性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信