Practical EMV Relay Protection
Andreea-Ina Radu, Tom Chothia, Christopher J. P. Newton, Ioana Boureanu, Liqun Chen
Abstract
Relay attackers can forward messages between a contactless EMV bank card and a shop reader, making it possible to wirelessly pickpocket money. To protect against this, Apple Pay requires a user’s fingerprint or Face ID to authorise payments, while Mastercard and Visa have proposed protocols to stop such relay attacks. We investigate transport payment modes and find that we can build on relaying to bypass the Apple Pay lock screen, and illicitly pay from a locked iPhone to any EMV reader, for any amount, without user authorisation. We show that Visa’s proposed relay-countermeasure can be bypassed using rooted smart phones. We analyse Mastercard’s relay protection, and show that its timing bounds could be more reliably imposed at the ISO 14443 protocol level, rather than at the EMV protocol level. With these insights, we propose a new relay-resistance protocol (L1RP) for EMV. We use the Tamarin prover to model mobile-phone payments with and without user authentication, and in different payment modes. We formally verify solutions to our attack suggested by Apple and Visa, and used by Samsung, and we verify that our proposed protocol provides protection from relay attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 761ea61b-762e-4def-aa74-2b1370333deaCited by top-tier papers8
- Formal verification of the PQXDH Post-Quantum key agreement protocol for end-to-end secure messagingKarthikeyan Bhargavan, Charlie Jacomme, Franziskus Kiefer, Rolfe SchmidtUSENIX Security 2024 · 27 citations
- A Formal Analysis of SCTP: Attack Synthesis and Patch VerificationJacob Ginesin, Max von Hippel, Evan Defloor, Cristina Nita-Rotaru et al.USENIX Security 2024 · 4 citations
- Provably Unlinkable Smart Card-based PaymentsSergiu Bursuc, Ross Horne, Sjouke Mauw, Semen YurkovCCS 2023 · 2 citations
- Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless PaymentsRaja Hasnain Anwar, Gerard DeCunha, Muhammad Taqi RazaUSENIX Security 2026
- Who Pays Whom? Anonymous EMV-Compliant Contactless PaymentsCharles Olivier-Anclin, Ioana Boureanu, Liqun Chen, Christopher J. P. Newton et al.USENIX Security 2025
Builds on7
- The EMV Standard: Break, Fix, VerifyDavid A. Basin, Ralf Sasse, Jorge Toro-PozoS&P 2021 · 69 citations
- Distance-Bounding Protocols: Verification without Time and LocationSjouke Mauw, Zach Smith, Jorge Toro-Pozo, Rolando Trujillo-RasuaS&P 2018 · 58 citations
- UWB with Pulse Reordering: Securing Ranging against Relay and Physical-Layer AttacksMridula Singh, Patrick Leu, Srdjan CapkunNDSS 2019 · 57 citations
- Card Brand Mixup Attack: Bypassing the PIN in non-Visa Cards by Using Them for Visa TransactionsDavid A. Basin, Ralf Sasse, Jorge Toro-PozoUSENIX Security 2021 · 32 citations
- Modelling and Analysis of a Hierarchy of Distance Bounding AttacksTom Chothia, Joeri de Ruiter, Ben SmythUSENIX Security 2018 · 25 citations
Related papers
- Security Analysis and Implementation of Relay-Resistant Contactless PaymentsIoana Boureanu, Tom Chothia, Alexandre Debant, Stéphanie DelauneCCS 2020 · 10 citations
- PURE: Payments with UWB RElay-protectionDaniele Coppola, Giovanni Camurati, Claudio Anliker, Xenia Hofmeier et al.USENIX Security 2024 · 5 citations
- Inducing Authentication Failures to Bypass Credit Card PINsDavid A. Basin, Patrick Schaller, Jorge Toro-PozoUSENIX Security 2023
- More is Less: Extra Features in Contactless Payments Break SecurityGeorge Pavlides, Anna Clee, Ioana Boureanu, Tom ChothiaUSENIX Security 2025
- Picking Up My Tab: Understanding and Mitigating Synchronized Token Lifting and Spending in Mobile PaymentXiaolong Bai, Zhe Zhou, XiaoFeng Wang, Zhou Li et al.USENIX Security 2017 · 34 citations
