首页> 外文OA文献 >Enhancing EMV Tokenisation with Dynamic Transaction Tokens
【2h】

Enhancing EMV Tokenisation with Dynamic Transaction Tokens

机译:使用动态交易令牌增强EMV令牌化

摘要

Europay MasterCard Visa (EMV) Tokenisation specification details how the risk involved in Personal Account Number (PAN) compromise can be prevented by using tokenisation. In this paper, we identify two main potential problem areas that raise concerns about the security of tokenised EMV contactless mobile payments, especially when the same token also called a static token is used to pay for all transactions. We then discuss five associated attack scenarios that would let an adversary compromise payment transactions. It is paramount to address these security concerns to secure tokenised payments, which is the main focus of the paper. We propose a solution that would enhance the security of this process when a smart phone is used to make a tokenised contactless payment. In our design, instead of using a static token in every transaction, a new dynamic token and a token cryptogram is used. The solution is then analysed against security and protocol objectives.Finally the proposed protocol is subjected to mechanical formal analysis using Scyther which did not find any feasible attacks within the bounded state space.
机译:Europay MasterCard Visa(EMV)令牌化规范详细介绍了如何通过使用令牌化来防止涉及个人帐号(PAN)泄露的风险。在本文中,我们确定了两个主要的潜在问题领域,这些领域引起了人们对令牌化EMV非接触式移动支付安全性的担忧,尤其是当使用同一令牌(也称为静态令牌)支付所有交易时。然后,我们讨论了五个相关的攻击方案,这些方案将使对手破坏支付交易。解决这些安全问题以确保令牌化付款至关重要,这是本文的重点。我们提出了一种解决方案,当使用智能手机进行令牌化非接触式支付时,该解决方案可以增强此过程的安全性。在我们的设计中,不是在每个事务中都使用静态令牌,而是使用了新的动态令牌和令牌密码。然后针对安全性和协议目标对解决方案进行分析。最后,使用Scyther对提议的协议进行机械形式分析,该分析在有限状态空间内未发现任何可行的攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号