Practical EMV Relay Protection
Andreea-Ina Radu, Tom Chothia, Christopher J. P. Newton, Ioana Boureanu, Liqun Chen
摘要
Relay attackers can forward messages between a contactless EMV bank card and a shop reader, making it possible to wirelessly pickpocket money. To protect against this, Apple Pay requires a user’s fingerprint or Face ID to authorise payments, while Mastercard and Visa have proposed protocols to stop such relay attacks. We investigate transport payment modes and find that we can build on relaying to bypass the Apple Pay lock screen, and illicitly pay from a locked iPhone to any EMV reader, for any amount, without user authorisation. We show that Visa’s proposed relay-countermeasure can be bypassed using rooted smart phones. We analyse Mastercard’s relay protection, and show that its timing bounds could be more reliably imposed at the ISO 14443 protocol level, rather than at the EMV protocol level. With these insights, we propose a new relay-resistance protocol (L1RP) for EMV. We use the Tamarin prover to model mobile-phone payments with and without user authentication, and in different payment modes. We formally verify solutions to our attack suggested by Apple and Visa, and used by Samsung, and we verify that our proposed protocol provides protection from relay attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Formal verification of the PQXDH Post-Quantum key agreement protocol for end-to-end secure messagingKarthikeyan Bhargavan, Charlie Jacomme, Franziskus Kiefer, Rolfe SchmidtUSENIX Security 2024 · 被引用 27 次
- A Formal Analysis of SCTP: Attack Synthesis and Patch VerificationJacob Ginesin, Max von Hippel, Evan Defloor, Cristina Nita-Rotaru 等USENIX Security 2024 · 被引用 4 次
- Provably Unlinkable Smart Card-based PaymentsSergiu Bursuc, Ross Horne, Sjouke Mauw, Semen YurkovCCS 2023 · 被引用 2 次
- Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless PaymentsRaja Hasnain Anwar, Gerard DeCunha, Muhammad Taqi RazaUSENIX Security 2026
- Who Pays Whom? Anonymous EMV-Compliant Contactless PaymentsCharles Olivier-Anclin, Ioana Boureanu, Liqun Chen, Christopher J. P. Newton 等USENIX Security 2025
它引用的顶会 Paper7
- The EMV Standard: Break, Fix, VerifyDavid A. Basin, Ralf Sasse, Jorge Toro-PozoS&P 2021 · 被引用 69 次
- Distance-Bounding Protocols: Verification without Time and LocationSjouke Mauw, Zach Smith, Jorge Toro-Pozo, Rolando Trujillo-RasuaS&P 2018 · 被引用 58 次
- UWB with Pulse Reordering: Securing Ranging against Relay and Physical-Layer AttacksMridula Singh, Patrick Leu, Srdjan CapkunNDSS 2019 · 被引用 57 次
- Card Brand Mixup Attack: Bypassing the PIN in non-Visa Cards by Using Them for Visa TransactionsDavid A. Basin, Ralf Sasse, Jorge Toro-PozoUSENIX Security 2021 · 被引用 32 次
- Modelling and Analysis of a Hierarchy of Distance Bounding AttacksTom Chothia, Joeri de Ruiter, Ben SmythUSENIX Security 2018 · 被引用 25 次
相关 Paper
- Security Analysis and Implementation of Relay-Resistant Contactless PaymentsIoana Boureanu, Tom Chothia, Alexandre Debant, Stéphanie DelauneCCS 2020 · 被引用 10 次
- PURE: Payments with UWB RElay-protectionDaniele Coppola, Giovanni Camurati, Claudio Anliker, Xenia Hofmeier 等USENIX Security 2024 · 被引用 5 次
- Inducing Authentication Failures to Bypass Credit Card PINsDavid A. Basin, Patrick Schaller, Jorge Toro-PozoUSENIX Security 2023
- More is Less: Extra Features in Contactless Payments Break SecurityGeorge Pavlides, Anna Clee, Ioana Boureanu, Tom ChothiaUSENIX Security 2025
- Picking Up My Tab: Understanding and Mitigating Synchronized Token Lifting and Spending in Mobile PaymentXiaolong Bai, Zhe Zhou, XiaoFeng Wang, Zhou Li 等USENIX Security 2017 · 被引用 34 次
