首页> 外文会议>Conference on Mobile and Secure Services >Two-factor authentication for android host card emulated contactless cards
【24h】

Two-factor authentication for android host card emulated contactless cards

机译:Android主机卡模拟非接触式卡的两因素身份验证

获取原文

摘要

With the introduction of Host Card Emulation (HCE) in Android 4.4 KitKat the Near Field Communication (NFC) card emulation mode took a twist. On one side, HCE allows for easier development and a shorter deployment path for contactless card services on the mobile phone (e.g. payment, ticketing, loyalty cards etc.). On the other side, it introduces new security issues since it does not intrinsically involve a secure element on the mobile phone. As an example, the Cipurse open ticketing standard for public transportation, published by OSPT, implies usage of a secure element for the authentication mechanism and key storage. How can Cipurse benefit from the advantages of HCE and still provide secure authentication and encryption of transferred data? We have designed a two-factor authentication mechanism that involves usage of the Universal Integrated Circuit Card (also known as the SIM card) as the secure second-factor that allows for the implementation of the Cipurse specification as a secure HCE application. The benefit is faster execution of the Cipurse emulated card but still with feasible security for many application areas.
机译:随着Android 4.4 KitKat中主机卡仿真(HCE)的引入,近场通信(NFC)卡仿真模式发生了变化。一方面,HCE使得移动电话上的非接触式卡服务(例如付款,票务,会员卡等)的开发更容易,部署路径更短。另一方面,它引入了新的安全问题,因为它本质上并不涉及移动电话上的安全元素。例如,由OSPT发布的用于公共交通的Cipurse公开票务标准意味着使用安全元素进行身份验证机制和密钥存储。 Cipurse如何从HCE的优势中受益并仍然提供对传输数据的安全身份验证和加密?我们设计了一种两因素身份验证机制,其中涉及将通用集成电路卡(也称为SIM卡)用作安全的第二因素,从而允许将Cipurse规范实现为安全的HCE应用程序。好处是Cipurse仿真卡的执行速度更快,但在许多应用领域仍具有可行的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号