基于emv的线下交易移动支付协议——具有相互认证能力

羅嘉寧, 楊明豪, 何宇承
{"title":"基于emv的线下交易移动支付协议——具有相互认证能力","authors":"羅嘉寧, 楊明豪, 何宇承","doi":"10.6159/IJSE.2015.(5-1).09","DOIUrl":null,"url":null,"abstract":"The standards for Europay, MasterCard and Visa (EMV) have been widely adopted by current major financial services corporations but there are certain security threats: (1) authentication is one-way only, i.e. from a reader to a card. (2) EMV-compatible contactless smartcards do not encrypt sensitive data in the mobile transactions, which allows attackers to steal the users' personal information. (3) During offline transactions, the merchants cannot verify whether a credit card has been revoked. In 2013, Yang proposed a protocol to enhance the security of EMV standards. Yang's method can perform mutual authentication between a point-of-sale (POS) and a credit card, but the users can exceed the credits after multiple offline transactions. To improve Yang's method, we propose a new offline transaction mechanism that is compatible with the EMV standards. In our scheme, a user is required to apply for a limited and divisible credits from a bank, and stores the credits into his NFC phone's security elements (SE). During an offline transaction, the user has to send his certificate and the specific amount of credits to the merchant. The merchant verifies user's certificate, collects the credits, and redeems the payments from the bank. Our protocol is suitable for the offline environment that accommodates multiple merchants; it prevents exceeding the limitation in multiple offline transactions; and it enhances the security of EMV standards.","PeriodicalId":14209,"journal":{"name":"International Journal of Science and Engineering","volume":"5 1","pages":"61-66"},"PeriodicalIF":0.0000,"publicationDate":"2015-03-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"EMV-based Mobile Payment Protocol for Offline Transaction - With the Ability of Mutual Authentication\",\"authors\":\"羅嘉寧, 楊明豪, 何宇承\",\"doi\":\"10.6159/IJSE.2015.(5-1).09\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The standards for Europay, MasterCard and Visa (EMV) have been widely adopted by current major financial services corporations but there are certain security threats: (1) authentication is one-way only, i.e. from a reader to a card. (2) EMV-compatible contactless smartcards do not encrypt sensitive data in the mobile transactions, which allows attackers to steal the users' personal information. (3) During offline transactions, the merchants cannot verify whether a credit card has been revoked. In 2013, Yang proposed a protocol to enhance the security of EMV standards. Yang's method can perform mutual authentication between a point-of-sale (POS) and a credit card, but the users can exceed the credits after multiple offline transactions. To improve Yang's method, we propose a new offline transaction mechanism that is compatible with the EMV standards. In our scheme, a user is required to apply for a limited and divisible credits from a bank, and stores the credits into his NFC phone's security elements (SE). During an offline transaction, the user has to send his certificate and the specific amount of credits to the merchant. The merchant verifies user's certificate, collects the credits, and redeems the payments from the bank. Our protocol is suitable for the offline environment that accommodates multiple merchants; it prevents exceeding the limitation in multiple offline transactions; and it enhances the security of EMV standards.\",\"PeriodicalId\":14209,\"journal\":{\"name\":\"International Journal of Science and Engineering\",\"volume\":\"5 1\",\"pages\":\"61-66\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2015-03-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"International Journal of Science and Engineering\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.6159/IJSE.2015.(5-1).09\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Journal of Science and Engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.6159/IJSE.2015.(5-1).09","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

Europay、MasterCard和Visa (EMV)的标准已被目前主要的金融服务公司广泛采用,但存在一定的安全威胁:(1)身份验证是单向的,即从读卡器到卡。(2)兼容emv的非接触式智能卡在移动交易中不加密敏感数据,使得攻击者可以窃取用户的个人信息。(3)线下交易时,商家无法验证信用卡是否被吊销。2013年,杨提出了一项协议,以增强EMV标准的安全性。杨的方法可以在销售点(POS)和信用卡之间进行相互认证,但用户可以在多次离线交易后超过信用额度。为了改进Yang的方法,我们提出了一种新的与EMV标准兼容的离线交易机制。在我们的方案中,用户需要向银行申请有限且可分割的积分,并将这些积分存储在NFC手机的安全元素(SE)中。在离线交易期间,用户必须将他的证书和具体的信用额度发送给商家。商家验证用户的证书,收取信用,并从银行兑换付款。我们的协议适用于可容纳多个商家的线下环境;防止在多个离线事务中超过限制;增强了EMV标准的安全性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
EMV-based Mobile Payment Protocol for Offline Transaction - With the Ability of Mutual Authentication
The standards for Europay, MasterCard and Visa (EMV) have been widely adopted by current major financial services corporations but there are certain security threats: (1) authentication is one-way only, i.e. from a reader to a card. (2) EMV-compatible contactless smartcards do not encrypt sensitive data in the mobile transactions, which allows attackers to steal the users' personal information. (3) During offline transactions, the merchants cannot verify whether a credit card has been revoked. In 2013, Yang proposed a protocol to enhance the security of EMV standards. Yang's method can perform mutual authentication between a point-of-sale (POS) and a credit card, but the users can exceed the credits after multiple offline transactions. To improve Yang's method, we propose a new offline transaction mechanism that is compatible with the EMV standards. In our scheme, a user is required to apply for a limited and divisible credits from a bank, and stores the credits into his NFC phone's security elements (SE). During an offline transaction, the user has to send his certificate and the specific amount of credits to the merchant. The merchant verifies user's certificate, collects the credits, and redeems the payments from the bank. Our protocol is suitable for the offline environment that accommodates multiple merchants; it prevents exceeding the limitation in multiple offline transactions; and it enhances the security of EMV standards.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
审稿时长
8 weeks
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信