首页> 美国政府科技报告 >Computing Science. Harvesting High Value Foreign Currency Transactions from EMV Contactless Cards without the PIN.
【24h】

Computing Science. Harvesting High Value Foreign Currency Transactions from EMV Contactless Cards without the PIN.

机译:计算科学。从没有pIN的EmV非接触式卡中获取高价值外币交易。

获取原文

摘要

In this paper we present an attack which allows fraudulent transactions to be collected from EMV contactless credit and debit cards without the knowledge of the cardholder. The attack exploits a previously unreported vulnerability in EMV protocol, which allows EMV contactless cards to approve unlimited value transactions without the cardholder's PIN when the transaction is carried out in a foreign currency. For example, we have found that Visa credit cards will approve foreign currency transactions for any amount up to 999,999.99 without the cardholder's PIN, this side-steps the L20 contactless transaction limit in the UK. In reality, the criminals would choose a value between 100 and 200, which is low enough to be within the victim's balance and not to raise suspicion, but high enough to make each attack worthwhile. This paper outlines a scenario in which fraudulent transaction details are transmitted over the Internet to a 'rogue merchant' who then uses the transaction data to take money from the victim's account. The attack described in this paper differs from previously identified attacks on EMV cards, in that it can be used to directly access money from EMV cards rather than to buy goods. The attack is novel in that it could be operated on a large scale with multiple attackers collecting fraudulent transactions for a central rogue merchant which can be located anywhere in the world where EMV payments are accepted.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号