Security Analysis and Implementation of Relay-Resistant Contactless Payments
Ioana Boureanu, Tom Chothia, Alexandre Debant, Stéphanie Delaune
Abstract
Contactless systems, such as the EMV (Europay, Mastercard and Visa) payment protocol, are vulnerable to relay attacks. The typical countermeasure to this relies on distance bounding protocols, in which a reader estimates an upper bound on its physical distance from a card by doing round-trip time (RTT) measurements. However, these protocols are trivially broken in the presence of rogue readers. At Financial Crypto 2019, we proposed two novel EMV-based relay-resistant protocols: they integrate distance-bounding with the use of hardware roots of trust (HWRoT) in such a way that correct RTT-measurements can no longer be bypassed. Our contributions are threefold: first, we design a calculus to model this advanced type of distance-bounding protocols integrated with HWRoT; as an additional novelty, our calculus is also the first to allow for mobility of cards and readers during a proximity-checking phase. Second, to make it possible to analyse these protocols via more standard mechanisms and tools, we consider a 2018 characterisation of distance-bounding security that does away with physical aspects and relies only on the causality of events; we cast it in our richer calculus and extend its theoretical guarantees to our more expressive models (with mobility, potentially rogue readers, and HWRoT). Due to this extension, we can carry out the security analysis in the standard protocol verification tool ProVerif. Third, we provide the first implementation of Mastercard's relay-resistant EMV protocol PayPass-RRP as well as one of its 2019 extension with HWRoT called PayBCR. We evaluate their efficiency and their robustness to relay attacks, in presence of both honest and rogue readers. Our experiments are the first to show that Mastercard's PayPass-RRP and its HWRoT-based extension PayBCR are both practical in preventing relay attacks of the magnitude shown thus-far in EMV.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3a982f88-d6da-48d5-b574-8d8dbf3508e8Cited by top-tier papers3
- Practical EMV Relay ProtectionAndreea-Ina Radu, Tom Chothia, Christopher J. P. Newton, Ioana Boureanu et al.S&P 2022 · 26 citations
- When HTTP 402 Meets the Blockchain: Risks on Emerging x402 PaymentsQinying Wang, Yong Yang, Yuan Chen, Shouling Ji et al.USENIX Security 2026
- "Tap" Without Tapping: A Tag Discovery Forgery Attack on Android NFCYilin Li, Jianliang Wu, Chaoshun Zuo, Qingchuan Zhao et al.USENIX Security 2026
Builds on2
Related papers
- PURE: Payments with UWB RElay-protectionDaniele Coppola, Giovanni Camurati, Claudio Anliker, Xenia Hofmeier et al.USENIX Security 2024 · 5 citations
- Post-Collusion Security and Distance BoundingSjouke Mauw, Zach Smith, Jorge Toro-Pozo, Rolando Trujillo-RasuaCCS 2019 · 12 citations
- Message Time of Arrival Codes: A Fundamental Primitive for Secure Distance MeasurementPatrick Leu, Mridula Singh, Marc Roeschlin, Kenneth G. Paterson et al.S&P 2020 · 31 citations
- A Bus Authentication and Anti-Probing Architecture Extending Hardware Trusted Computing Base Off CPU Chips and BeyondZhenyu Xu, Thomas Mauldin, Zheyi Yao, Shuyi Pei et al.ISCA 2020 · 23 citations
- Reducing HSM Reliance in Payments through Proxy Re-EncryptionSivanarayana Gaddam, Atul Luykx, Rohit Sinha, Gaven J. WatsonUSENIX Security 2021 · 2 citations
