Secret State Leakage Attacks and Their Impacts on EMV Contactless Payment Apps
Jesse Chen, Rubin Yuchan Yang, Ahmad Musa, Syed Rafiul Hussain, Omar Chowdhury, Sazzadur Rahaman
Abstract
This paper analyzes the security of EMV contactless mobile payment (ECM) apps, virtualization of physical EMV chip cards, in a less explored but relevant threat model. In this threat model, a local adversary such as the legitimate ECM app user (possibly, with root privileges) launches attacks to expose the EMV protocol's internal secret states from the app. Such secret leakage combined with the attacker's capability to modify the ECM app behavior can be exploitable for potentially self-serving purposes (e.g., double-spending). To formally study such secret state leakage attacks (SecStLeak) and their impacts, we pose the minimal satisfying cut-set identification problem for the EMV contactless protocol design where the goal is identifying the minimal number of the protocol's secret state fields whose leakage can entail different attacks. We solve this problem by proposing a meta-level protocol analysis approach.
Our analysis identified 4 minimal sets of secret state fields that ECM app developers must protect to prevent such attacks. We analyzed 136 Android ECM apps and identified all secret fields for 2 of the 4 minimal sets across 24 apps. In addition, one can leak a third minimal set in 3 of the 24 apps. The potential impact is significant, with these 24 apps having 82M downloads, 6 coming from developing countries, and 3 operating in a country without support for Google Wallet. To establish our findings' real-world applicability, we demonstrate a core guarantee-violating end-to-end attack on a real ECM app in an isolated test environment. This successful exploitation motivated us to study how developers in the real world protect the secret state fields belonging to the 4 minimal sets to thwart SecStLeak attacks. We observe that a majority of these apps, contrary to EMV standard's recommendation, rely on circumventable, sub-optimal software-only defenses.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on21
- A Formal Analysis of 5G AuthenticationDavid A. Basin, Jannik Dreier, Lucca Hirschi, Sasa Radomirovic et al.CCS 2018 · 428 citations
- A Comprehensive Symbolic Analysis of TLS 1.3Cas Cremers, Marko Horvat, Jonathan Hoyland, Sam Scott et al.CCS 2017 · 247 citations
- LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTESyed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, Elisa BertinoNDSS 2018 · 225 citations
- CryptoGuard: High Precision Detection of Cryptographic Vulnerabilities in Massive-sized Java ProjectsSazzadur Rahaman, Ya Xiao, Sharmin Afrose, Fahad Shaon et al.CCS 2019 · 159 citations
- Statistical Deobfuscation of Android ApplicationsBenjamin Bichsel, Veselin Raychev, Petar Tsankov, Martin T. VechevCCS 2016 · 128 citations
Related papers
- The EMV Standard: Break, Fix, VerifyDavid A. Basin, Ralf Sasse, Jorge Toro-PozoS&P 2021 · 69 citations
- More is Less: Extra Features in Contactless Payments Break SecurityGeorge Pavlides, Anna Clee, Ioana Boureanu, Tom ChothiaUSENIX Security 2025
- Card Brand Mixup Attack: Bypassing the PIN in non-Visa Cards by Using Them for Visa TransactionsDavid A. Basin, Ralf Sasse, Jorge Toro-PozoUSENIX Security 2021 · 32 citations
- Picking Up My Tab: Understanding and Mitigating Synchronized Token Lifting and Spending in Mobile PaymentXiaolong Bai, Zhe Zhou, XiaoFeng Wang, Zhou Li et al.USENIX Security 2017 · 34 citations
- Who Pays Whom? Anonymous EMV-Compliant Contactless PaymentsCharles Olivier-Anclin, Ioana Boureanu, Liqun Chen, Christopher J. P. Newton et al.USENIX Security 2025
