[論文レビュー] Survey of Strong Authentication Approaches for Mobile Proximity and Remote Wallet Applications - Challenges and Evolution
本論文は、モバイル近接およびリモートウォレットアプリケーションにおける強力な認証手法を調査し、既存手法の課題と、デバイスファイラーイングおよびEMVCoトークン化への進化を分析する。本稿は、デバイス属性を用いたコンテキストベースの多要素認証が今後も優勢であると提案するが、将来的なトークンシステムでは、強力な認証を実現するためにデバイスファイラーイングが不可欠となるだろう。
Wallet may be described as container application used for configuring, accessing and analysing data from underlying payment application(s). There are two dominant types of digital wallet applications, proximity wallet and remote wallet. In the payment industry, one often hears about authentication approach for proximity or remote wallets or the underlying payment applications separately, but there is no such approach, as per our knowledge, for combined wallet, the holder application. While Secure Element (SE) controlled by the mobile network operator (i.e., SIM card) may ensure strong authentication, it introduces strong dependencies among business partners in payments and hence is not getting fraction. Embedded SE in the form of trusted execution environment [3, 4, 5] or trusted computing [24] may address this issue in future. But such devices tend to be a bit expensive and are not abundant in the market. Meanwhile, for many years, context based authentication involving device fingerprinting and other contextual information for conditional multi-factor authentication, would prevail and would remain as the most dominant and strong authentication mechanism for mobile devices from various vendors in different capability and price ranges. EMVCo payment token standard published in 2014 tries to address security of wallet based payment in a general way. The authors believe that it is quite likely that EMVCo payment token implementations would evolve in course of time in such a way that token service providers would start insisting on device fingerprinting as strong means of authentication before issuing one-time-use payment token. This paper talks about challenges of existing authentication mechanisms used in payment and wallet applications, and their evolution.
研究の動機と目的
- モバイル近接およびリモートウォレットアプリケーションにおける強力な認証の課題を分析すること。
- SIMベースのセキュアエレメントに依存する既存の認証メカニズムの限界を検討すること。
- 認証の進化がデバイスファイラーイングおよびコンテキストベースの多要素手法へと向かうプロセスを調査すること。
- 将来の認証実務を形作る上で、EMVCo決済トークン化といった新規標準の果たす役割を評価すること。
- 多様なモバイルデバイスエコシステムにおける、ハードウェア依存型からソフトウェアベースの強力な認証へのシフトを特定すること。
提案手法
- 近接およびリモートウォレットを対象としたモバイルウォレットアプリケーションにおける既存の認証メカニズムを調査すること。
- セキュアエレメント(SE)および Trusted Execution Environments(TEE)が強力な認証を可能にする役割を評価すること。
- ベンダーおよび事業者依存性によるSIMベースのSEの限界を分析すること。
- デバイスファイラーイングおよびコンテキスト信号を用いたコンテキストベースの認証が、代替手段として優勢である理由を調査すること。
- 一般向けウォレットセキュリティのフレームワークとしてのEMVCo決済トークン標準(2014年)を検討すること。
- 将来的なトレンドとして、トークンサービスポーバーが一時使用用トークンを発行する前にデバイスファイラーイングを要件とする可能性を予測すること。
実験結果
リサーチクエスチョン
- RQ1モバイル近接およびリモートウォレットにおける強力な認証を実装する際の主な課題は何ですか?
- RQ2SIMベースのセキュアエレメントのようなハードウェアベースのソリューションは、相互運用性および市場採用にどのように影響を与えますか?
- RQ3なぜ、多様なモバイルデバイスエコシステムにおいてデバイスファイラーイングが主要な認証メカニズムとなると予想されるのですか?
- RQ4EMVCo決済トークン標準は、デバイスレベルの認証を統合するために、どのように進化する可能性がありますか?
- RQ5事業者制御のSEからソフトウェアベースの信頼できる環境への移行が、ウォレットセキュリティに及ぼす影響は何ですか?
主な発見
- SIMベースのセキュアエレメントは強力な認証を提供するが、支払いパートナー間の強い依存関係を生じさせ、広範な採用を制限する。
- TEEまたは信頼できるコンピューティングを介した埋め込みセキュアエレメントは、有望な今後の道筋を示しているが、依然として高価であり、広く利用可能ではない。
- 低コストの多様なモバイルデバイスにおいて、デバイスファイラーイングとコンテキスト情報の組み合わせが、主な強力な認証メカニズムとして支配的になると予想される。
- EMVCo決済トークン標準(2014年)は、ウォレットベースの決済の一般的なセキュリティフレームワークを提供しており、将来的な進化の余地がある。
- トークンサービスポーバーが、一時使用用決済トークンを発行する前にデバイスファイラーイングを前提条件とする可能性が高まっている。
- スケーラビリティの向上、コスト削減、および広範なデバイス互換性の必要性から、ハードウェア中心の認証からソフトウェアベースの認証への移行が進んでいる。
より良い研究を、今すぐ始めましょう
論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。
クレジットカード登録不要
このレビューはAIが作成し、人間の編集者が確認しました。