USENIX Security2017Top-tier venue
Picking Up My Tab: Understanding and Mitigating Synchronized Token Lifting and Spending in Mobile Payment
Xiaolong Bai, Zhe Zhou, XiaoFeng Wang, Zhou Li, Xianghang Mi, Nan Zhang, Tongxin Li, Shi-Min Hu, Kehuan Zhang
Abstract
Mobile off-line payment enables purchase over the counter even in the absence of reliable network connections. Popular solutions proposed by leading payment service providers (e.g., Google, Amazon, Samsung, Apple) rely on direct communication between the payer's device and the POS system, through Near-Field Communication (NFC), Magnetic Secure Transaction (MST), audio and QR code. Although pre-cautions have been taken to protect the payment transactions through these channels, their security implications are less understood, particularly in the presence of unique threats to this new e-commerce service.
In the paper, we report a new type of over-the-counter payment frauds on mobile off-line payment, which exploit the designs of existing schemes that apparently fail to consider the adversary capable of actively affecting the payment process. Our attack, called Synchronized Token Lifting and Spending (STLS), demonstrates that an active attacker can sniff the payment token, halt the ongoing transaction through various means and transmit the token quickly to a colluder to spend it in a different transaction while the token is still valid. Our research shows that such STLS attacks pose a realistic threat to popular offline payment schemes, particularly those meant to be backwardly compatible, like Samsung Pay and AliPay.
To mitigate the newly discovered threats, we propose a new solution called POSAUTH. One fundamental cause of the STLS risk is the nature of the communication channels used by the vulnerable mobile off-line payment schemes, which are easy to sniff and jam, and more importantly, unable to support a secure mutual challenge-response protocols since information can only be transmitted in one-way. POSAUTH addresses this issue by incorporating one unique ID of the current POS terminal into the generation of payment tokens by requiring a quick scan- * The two lead authors are ordered alphabetically.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b18cd3b2-7f71-47b5-b019-acaec82fb750Cited by top-tier papers8
- MagCode: NFC-Enabled Barcodes for NFC-Disabled SmartphonesDonghui Dai, Zhenlin An, Qingrui Pan, Lei YangMobiCom 2023 · 14 citations
- ScreenID: Enhancing QRCode Security by Fingerprinting ScreensYijie Li, Yi-Chao Chen, Xiaoyu Ji, Hao Pan et al.INFOCOM 2021 · 7 citations
- Do You See How I Pose? Using Poses as an Implicit Authentication Factor for QR Code PaymentChuxiong Wu, Qiang ZengUSENIX Security 2024 · 2 citations
- What You Decode Depends on Where You Stand: Distance-Based Optical QR CodePulkit Garg, Robin Verma, Somitra Sanadhya, Gaurav GuptaUSENIX Security 2026
- Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless PaymentsRaja Hasnain Anwar, Gerard DeCunha, Muhammad Taqi RazaUSENIX Security 2026
Related papers
- Practical EMV Relay ProtectionAndreea-Ina Radu, Tom Chothia, Christopher J. P. Newton, Ioana Boureanu et al.S&P 2022 · 26 citations
- When Authorization Loses Its Meaning: Breaking and Fixing Third-Party Online PaymentsYongkang Xiao, Jing Chen, Min Shi, Kun He et al.USENIX Security 2026
- Secret State Leakage Attacks and Their Impacts on EMV Contactless Payment AppsJesse Chen, Rubin Yuchan Yang, Ahmad Musa, Syed Rafiul Hussain et al.S&P 2026
- Inducing Authentication Failures to Bypass Credit Card PINsDavid A. Basin, Patrick Schaller, Jorge Toro-PozoUSENIX Security 2023
- More is Less: Extra Features in Contactless Payments Break SecurityGeorge Pavlides, Anna Clee, Ioana Boureanu, Tom ChothiaUSENIX Security 2025
