A Practical Set-Membership Proof for Privacy-Preserving NFC Mobile Ticketing

نویسندگان

  • Ghada Arfaoui
  • Jean-François Lalande
  • Jacques Traoré
  • Nicolas Desmoulins
  • Pascal Berthomé
  • Said Gharout
چکیده

To ensure the privacy of users in transport systems, researchers are working on new protocols providing the best security guarantees while respecting functional requirements of transport operators. In this paper , we design a secure NFC m-ticketing protocol for public transport that preserves users’ anonymity and prevents transport operators from tracing their customers’ trips. To this end, we introduce a new practical set-membership proof that does not require provers nor verifiers (but in a specific scenario for verifiers) to perform pairing computations. It is therefore particularly suitable for our (ticketing) setting where provers hold SIM/UICC cards that do not support such costly computations. We also propose several optimizations of Boneh-Boyen type signature schemes, which are of independent interest, increasing their performance and efficiency during NFC transactions. Our m-ticketing protocol offers greater flexibility compared to previous solutions as it enables the post-payment and the off-line validation of m-tickets. By implementing a prototype using a standard NFC SIM card, we show that it fulfils the stringent functional requirement imposed by transport operators whilst using strong security parameters. In particular, a validation can be completed in 184.25ms when the mobile is switched on, and in 266.52ms when the mobile is switched off or its battery is flat.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Critical Business Model Issues in Deploying NFC Technology for Mobile Services: Case Mobile Ticketing

New mobile ticketing services include travel card functionality in mobile phones, providing users with numerous benefits. However, several open issues still pose limitations for these services, including the diffusion of the enabling technology called Near Field Communication (NFC), concerns about security and privacy, as well as uncertainties in the related value networks and business models. ...

متن کامل

Considering Context in Mobile Ticketing

This paper discusses the role of context in a mobile ticketing system for public transport. Although context-awareness in this domain promises benefits such as simplified and smarter usersystem interaction, the context of telecommunication services raises issues of security and privacy. We present a system architecture utilizing a privacy enhancing protocol that allows secure exchange of sensit...

متن کامل

Privacy-preserving E-ticketing Systems for Public Transport Based on RFID/NFC Technologies

Pervasive digitization of human environment has dramatically changed our everyday lives. New technologies which have become an integral part of our daily routine have deeply affected our perception of the surrounding world and have opened qualitatively new opportunities. In an urban environment, the influence of such changes is especially tangible and acute. For example, ubiquitous computing (a...

متن کامل

On Protection of the User's Privacy in Ubiquitous E-ticketing Systems based on RFID and NFC Technologies

The issues of customer privacy in e-ticketing systems for public transport based on RFID/NFC technologies are addressed in this paper. More specifically, having described the target system, the specific privacy threats are identified and respectively classified. This is performed by analyzing the system under concern against the specifically defined privacy properties (pseudonymity, confidentia...

متن کامل

Application of Near Field Communication Technology for Mobile Airline Ticketing

Problem statement: Near Field Communication (NFC) technology opens up exciting new usage scenarios for mobile devices based platform. Users of NFC-enabled devices can simply point or touch their devices to other NFC-enabled elements in the environment to communicate with them (‘contactless’), making application and data usage easy and convenient. Approach: The study describes the characteristic...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • PoPETs

دوره 2015  شماره 

صفحات  -

تاریخ انتشار 2015