首页> 外文OA文献 >POS Terminal Authentication Protocol to Protect EMV Contactless Payment Cards
【2h】

POS Terminal Authentication Protocol to Protect EMV Contactless Payment Cards

机译:POS终端身份验证协议,用于保护EMV非接触式支付卡

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

The original EMV protocol was designed to operate in a situation where the card holder removes their card from their wallet and insert the card into a Point of Sale (POS) terminal. The protocol operates predominantly in plaintext which was not a problem because the attackers needed to tamper with the POS to gain access to the information on the card. The introduction of contactless EMV cards exposes the mainly plaintext EMV protocol to a wireless interface. This allows attackers to use an off-the-shelf NFC reader to access the card without the cardholders knowledge and potentially whilst the card is still in their wallet. Research has demonstrated that contactless EMV cards are vulnerable to various attacks carried out using off-the- shelf equipment which is both cheap and easy to obtain. The proposed solution addresses these issues by having the card request that any NFC reader, attempting to initiate communication, must authenticate itself as a genuine bank issued POS. The POS does this using a Bank issued private key to sign a nonce provided by the card.
机译:原始的EMV协议旨在在持卡人将其卡从钱包中取出并将其插入销售点(POS)终端的情况下运行。该协议主要以明文形式运行,这不是问题,因为攻击者需要篡改POS才能访问卡上的信息。非接触式EMV卡的引入使主要的纯文本EMV协议暴露于无线接口。这使攻击者可以使用现成的NFC读卡器在持卡人不知情的情况下,甚至在卡仍在其钱包中的情况下访问卡。研究表明,非接触式EMV卡容易受到使用廉价且易于获得的现成设备进行的各种攻击的影响。所提出的解决方案通过让卡要求任何NFC读取器尝试发起通信,都必须将其自身认证为真正的银行发行的POS,从而解决了这些问题。 POS使用银行发行的私钥对卡提供的现时签名进行签名。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号