【24h】

Risks of Offline Verify PIN on Contactless Cards

机译:离线验证销的风险无接触卡

获取原文

摘要

Contactless card payments are being introduced around the world allowing customers to use a card to pay for small purchases by simply placing the card onto the Point of Sale terminal. Contactless transactions do not require verification of the cardholder's PIN. However our research has found the redundant verify PIN functionality is present on the most commonly issued contactless credit and debit cards currently in circulation in the UK. This paper presents a plausible attack scenario which exploits contactless verify PIN to give unlimited attempts to guess the cardholder's PIN without their knowledge. It also gives experimental data to demonstrate the practical viability of the attack as well as references to support our argument that contactless verify PIN is redundant functionality which compromises the security of payment cards and the cardholder.
机译:无与伦比的卡支付正在世界各地推出,允许客户使用卡来支付小型购买,只需将卡放在销售点终端。非接触式事务不需要验证持卡人的PIN。但是,我们的研究发现,冗余验证引脚功能存在于英国最常用的非接触式信贷和借记卡中存在的冗余验证PIN功能。本文介绍了一种合理的攻击情景,它利用非接触式验证PIN,以无限制地尝试猜测持卡人的销钉,无需了解。它还给出了实验数据,以证明攻击的实际活力以及支持我们的论点的参考,即非接触式验证引脚是冗余功能,损害支付卡和持卡人的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号