When Authorization Loses Its Meaning: Breaking and Fixing Third-Party Online Payments
Yongkang Xiao, Jing Chen, Min Shi, Kun He, Qiyi Deng, Ruiying Du
摘要
Third-party online payment systems, such as Alipay and PSPB, constitute critical infrastructure for modern e-commerce. However, their security rests on the unrealistic assumption of fully trusted communication channels. While prior studies have identified isolated vulnerabilities, a systematic formal analysis of payment protocol security remains absent. This paper presents formal security models for six third-party payment protocols, spanning three major payment scenarios and two dominant payment service providers. Our analysis reveals a fundamental design flaw: whenever channel integrity is compromised between the merchant client, merchant server, or payment system, order tampering attacks become feasible. We validate this threat on Android, where over 20% of tested merchant applications allow order tampering through implicit Intent hijacking. To mitigate this threat, we propose user-side order authentication, where per-user-merchant key pairs cryptographically bind consent to order semantics. Formal verification demonstrates its resilience against identified attacks under weak channel assumptions. By bridging formal methods and empirical analysis, this work offers actionable guidance for standardizing secure payment protocols.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper14
- A Formal Analysis of 5G AuthenticationDavid A. Basin, Jannik Dreier, Lucca Hirschi, Sasa Radomirovic 等CCS 2018 · 被引用 428 次
- A Comprehensive Symbolic Analysis of TLS 1.3Cas Cremers, Marko Horvat, Jonathan Hoyland, Sam Scott 等CCS 2017 · 被引用 247 次
- Component-Based Formal Analysis of 5G-AKA: Channel Assumptions and Session ConfusionCas Cremers, Martin Dehnel-WildNDSS 2019 · 被引用 131 次
- Automated Analysis and Verification of TLS 1.3: 0-RTT, Resumption and Delayed AuthenticationCas Cremers, Marko Horvat, Sam Scott, Thyla van der MerweS&P 2016 · 被引用 128 次
- The EMV Standard: Break, Fix, VerifyDavid A. Basin, Ralf Sasse, Jorge Toro-PozoS&P 2021 · 被引用 69 次
相关 Paper
- Messy States of Wiring: Vulnerabilities in Emerging Personal Payment SystemsJiadong Lou, Xu Yuan, Ning ZhangUSENIX Security 2021 · 被引用 4 次
- A Formal Security Analysis of the W3C Web Payment APIs: Attacks and VerificationQuoc Huy Do, Pedram Hosseyni, Ralf Küsters, Guido Schmitz 等S&P 2022 · 被引用 6 次
- Maginot Line: Assessing a New Cross-app Threat to PII-as-Factor Authentication in Chinese Mobile AppsFannv He, Yan Jia, Jiayu Zhao, Yue Fang 等NDSS 2024
- Picking Up My Tab: Understanding and Mitigating Synchronized Token Lifting and Spending in Mobile PaymentXiaolong Bai, Zhe Zhou, XiaoFeng Wang, Zhou Li 等USENIX Security 2017 · 被引用 34 次
- Practical EMV Relay ProtectionAndreea-Ina Radu, Tom Chothia, Christopher J. P. Newton, Ioana Boureanu 等S&P 2022 · 被引用 26 次
