NFC Payment Spy: A Privacy Attack on Contactless Payments

نویسندگان

  • Maryam Mehrnezhad
  • Mohammed Aamir Ali
  • Feng Hao
  • Aad P. A. van Moorsel
چکیده

In a contactless transaction, when more than one card is presented to the payment terminal’s field, the terminal does not know which card to choose to proceed with the transaction. This situation is called card collision. EMV (which is the primary standard for smart card payments) specifies that the reader should not proceed when it detects a card collision and that instead it should notify the payer. In comparison, the ISO/IEC 14443 standard specifies that the reader should choose one card based on comparing the UIDs of the cards detected in the field. However, our observations show that the implementation of contactless NFC readers in practice does not follow EMV’s card collision algorithm, nor does it match the card collision procedure specified in ISO. Due to this inconsistency between the implementation and the standards, we show an attack that may compromise the user’s privacy by collecting the user’s payment details. We design and implement a malicious app simulating an NFC card which the user needs to install on her phone. When she aims to pay contactlessly while placing her card close to her phone, this app engages with the terminal before the card does. Although the terminal detects a card collision (the app essentially acts like a card), it proceeds with the EMV protocol. We show the app can retrieve from the terminal the transaction data, which include information about the payment such as the amount and date. The experimental results show that our app can effectively spy on contactless payment transactions, winning the race condition caused by card collisions around 66% when testing with different cards. By suggesting these attacks we raise awareness of privacy and security issues in the specifications, standardisation and implementations of contactless cards and readers.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Value-based Adoption of Contactless near Field Communication (nfc) Payments: an Empirical Investigation

The objective of this study is to investigate empirically the adoption of credit card contactless payments with smartphones. Contactless Near Field Communication (NFC) mobile payments, that are sought to develop exponentially worldwide in the near future due to their unquestionable advantages, may also face some user doubts. To investigate consumer possible positive and negative perceptions abo...

متن کامل

An Off-the-shelf Relay Attack in a Contactless Payment Solution

The enhanced Radio-Frequency Identification (RFID) technology called Near Field Communication (NFC), is a standards-based wireless communication technology. Passive NFC devices, such as contactless smart cards use NFC to communicate with other devices without any physical connection, or an internal battery source, deriving power inductively via the radio field generated by the NFC reader device...

متن کامل

A quantitative evaluation of NFC based contactless payment systems in retail

Near Field Communication (NFC) technology allows for the implementation of novel contactless payment systems in stationary retail. In this paper, we quantitatively analyze the impact of such systems on a retailer's payment costs on the example of real-world data from a Swiss food retailer. Our results indicate that the introduction of contactless payment under current card fee models would in v...

متن کامل

Practical Experiences on NFC Relay Attacks with Android: Virtual Pickpocketing Revisited

Near Field Communication (NFC) is a short-range contactless communication standard recently emerging as cashless payment technology. However, NFC has been proved vulnerable to several threats, such as eavesdropping, data modification, and relay attacks. A relay attack forwards the entire wireless communication, thus communicating over larger distances. In this paper, we review and discuss feasi...

متن کامل

Factors influencing the intention to adopt NFC mobile payments - A South African perspective

Near-field communication (NFC) is an emerging technology that is receiving global attention. NFC mobile payments are being deployed by many hardware vendors, technology companies and financial institutions. Their aim is to facilitate the use of mobile phones as a contactless payment device. A problem is the uncertainty around consumer adoption of this emerging technology. In this study we exami...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2016