An Online Security Protocol for NFC Payment Formally Analyzed by The Scyther Tool - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2016

An Online Security Protocol for NFC Payment Formally Analyzed by The Scyther Tool

Nour El Madhoun
Fouad Amine Guenane
  • Fonction : Auteur
  • PersonId : 971675
Guy Pujolle

Résumé

Nowadays, NFC technology is integrated into bank cards, smartphones and sales point terminals in order to immediately execute payment transactions without any physical contact. EMV is the standard intended to secure both contact (traditional) and contactless-NFC payment operations. In fact, researchers in recent years have detected some security vulnerabilities in this protocol (EMV). Therefore, in this paper, we introduce the risks entailed by the vulnerabilities of EMV and particularly those at stake in the case of NFC payment. Hence, in order to overcome EMV weaknesses, we propose a new security protocol based on an online communication with a trusted entity. The proposal is destined to secure contactless-NFC payment transactions using NFC bank cards that are unconnected client payment devices (without Wi-Fi or 4G). A security verification tool called Scyther is used to analyze the correctness of the proposal.
Fichier non déposé

Dates et versions

hal-01276921 , version 1 (21-02-2016)

Identifiants

  • HAL Id : hal-01276921 , version 1

Citer

Nour El Madhoun, Fouad Amine Guenane, Guy Pujolle. An Online Security Protocol for NFC Payment Formally Analyzed by The Scyther Tool. The Second IEEE International Conference On Mobile And Secure Services, Feb 2016, Gainesville, Florida, United States. ⟨hal-01276921⟩
306 Consultations
0 Téléchargements

Partager

Gmail Facebook X LinkedIn More