首页> 外文会议>IEEE International Conference on Big Data Science and Engineering >Extending EMV Tokenised Payments to Offline-Environments
【24h】

Extending EMV Tokenised Payments to Offline-Environments

机译:将EMV授予拨款到离线环境

获取原文

摘要

Tokenisation has been adopted by the payment industry as a method to prevent Personal Account Number (PAN) compromise in EMV (Europay MasterCard Visa) transactions. The current architecture specified in EMV tokenisation requires online connectivity during transactions. However, it is not always possible to have online connectivity. We identify three main scenarios where fully offline transaction capability is considered to be beneficial for both merchants and consumers. Scenarios include making purchases in locations without online connectivity, when a reliable connection is not guaranteed, and when it is cheaper to carry out offline transactions due to higher communication/payment processing costs involved in online approvals. In this study, an offline contactless mobile payment protocol based on EMV tokenisation is proposed. The aim of the protocol is to address the challenge of providing secure offline transaction capability when there is no online connectivity on either the mobile or the terminal. The solution also provides end-to-end encryption to provide additional security for transaction data other than the token. The protocol is analysed against protocol objectives and we discuss how the protocol can be extended to prevent token relay attacks. The proposed solution is subjected to mechanical formal analysis using Scyther. Finally, we implement the protocol and obtain performance measurements.
机译:支付行业已采用代价作为防止在EMV(Euroure MasterCard Visa)交易中的个人帐号(PAN)妥协的方法。 EMV标记中指定的当前体系结构需要在交易期间的在线连接。但是,并不总是有在线连接。我们确定三个主要方案,即完全离线交易能力被认为是有利于商家和消费者的有益。场景包括在没有在线连接的情况下在没有在线连接的位置进行购买,并且由于在线批准所涉及的沟通/支付处理成本更便宜而开展离线交易。在本研究中,提出了一种基于EMV标记的离线非接触式移动支付协议。该协议的目的是解决在移动或终端上没有在线连接时提供安全的离线交易能力的挑战。该解决方案还提供端到端加密,以便为令牌以外的事务数据提供额外的安全性。通过协议目标分析该协议,我们讨论如何扩展协议以防止令牌继电器攻击。使用Systher进行所提出的解决方案进行机械正式分析。最后,我们实施协议并获得性能测量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号