Skip to main content
QUICK REVIEW

[논문 리뷰] Security of Electronic Payment Systems: A Comprehensive Survey

Siamak Solat|arXiv (Cornell University)|2017. 01. 17.
Cryptography and Data Security참고 문헌 32인용 수 15
한 줄 요약

이 종합적 서베이는 전자 결제 시스템의 보안을 평가하며, 카드 현장 결제(EMV), 카드 비현장 결제(3D Secure, EMV/CAP), 접촉식(비접촉, Apple Pay), 블록체인 기반(비트코인) 시스템을 분석한다. 오프라인 스마트 카드 인증에서 특히 심각한 취약점을 밝혀내며, 무조건적 보안을 달성하기 위해 강력한 암호화, 토큰화, 블라인드 서명, 양자 키 분배를 주장한다.

ABSTRACT

This comprehensive survey deliberated over the security of electronic payment systems. In our research, we focused on either dominant systems or new attempts and innovations to improve the level of security of the electronic payment systems. This survey consists of the Card-present (CP) transactions and a review of its dominant system i.e. EMV including several researches at Cambridge university to designate variant types of attacks against this standard which demonstrates lack of a secure "offline" authentication method that is one of the main purpose of using the smart cards instead of magnetic stripe cards which are not able to participate in authentication process, the evaluation of the EMV migration from RSA cryptosystem to ECC based cryptosystem 3. The evaluation of the Card-not-present transactions approaches including 3D Secure, 3D SET, SET/EMV and EMV/CAP, the impact of concept of Tokenization and the role of Blind Signatures schemes in electronic cash and E-payment systems, use of quantum key distribution (QKD) in electronic payment systems to achieve unconditional security rather than only computational assurance of the security level by using traditional cryptography, the evaluation of Near Field Communication (NFC) and the contactless payment systems such as Google wallet, Android Pay and Apple Pay, the assessment of the electronic currency and peer to peer payment systems such as Bitcoin. The criterion of our survey for the measurement and the judgment about the quality of the security in electronic payment systems was this quote: "The security of a system is only as strong as its weakest link"

연구 동기 및 목표

  • 주요 및 신규 전자 결제 시스템의 보안 상태를 분석하기 위해.
  • 특히 EMV 스마트 카드의 오프라인 인증에서 발생하는 체계적 취약점을 특정하기 위해.
  • 3D Secure, EMV/CAP, 토큰화와 같은 현대 프로토콜이 사기 방지를 위해 얼마나 효과적인지 평가하기 위해.
  • 고급 암호화(예: ECC, 블라인드 서명)와 양자 키 분배가 무조건적 보안을 달성하는 데 어떻게 기여할 수 있는지 탐색하기 위해.
  • 비접촉 결제 시스템(예: Apple Pay, Google Wallet)과 비트코인과 같은 탈중앙화 시스템의 보안을 평가하기 위해.

제안 방법

  • 케임브리지 대학교에서 시연된 EMV 표준 및 사이드 채널 공격에 대한 체계적 리뷰.
  • EMV에서 RSA에서 ECC로의 이행이 효율성과 보안 향상에 기여하는지 평가.
  • 카드 비현장 거래를 위한 3D Secure, 3D SET, SET/EMV, EMV/CAP 프로토콜 분석.
  • 전자 화폐 시스템의 프라이버시와 보안 향상을 위해 토큰화 및 블라인드 서명 체계 분석.
  • 정보 이론적 보안을 달성하기 위한 양자 키 분배(QKD)의 가능성 조사.
  • Apple Pay 및 안드로이드 페이를 포함한 NFC 기반 비접촉 결제 시스템의 위협 모델과 구현 결함에 초점을 맞춘 평가.

실험 결과

연구 질문

  • RQ1왜 마그네틱 스트립을 대체한 이후에도 EMV 스마트 카드의 오프라인 인증은 여전히 취약한 고리인가?
  • RQ23D Secure와 EMV/CAP는 카드 비현장 사기 방지를 위해 얼마나 효과적인가?
  • RQ3토큰화와 블라인드 서명은 전자 결제의 보안과 프라이버시를 어느 정도 향상시킬 수 있는가?
  • RQ4양자 키 분배(QKD)는 전자 결제 시스템에서 무조건적 보안을 제공할 수 있는가?
  • RQ5Apple Pay 및 구글 월릿과 같은 NFC 기반 비접촉 결제 시스템에서의 주요 취약점은 무엇인가?

주요 결과

  • EMV의 오프라인 인증 메커니즘은 사이드 채널 공격 및 오류 주입 공격에 취약하여 주요 보안 목표를 뒤흔든다.
  • EMV에서 RSA에서 ECC로의 이행은 성능과 보안 향상을 가져오지만, 오프라인 인증의 근본적 결함을 해결하지 못한다.
  • 3D Secure 및 EMV/CAP 프로토콜은 사용성 문제를 겪으며 중간자 공격에 취약하다.
  • 토큰화는 전자상거래 거래에서 카드 데이터 노출 위험을 크게 줄인다.
  • 블라인드 서명 체계는 프라이버시를 보장하는 전자 화폐 시스템을 가능하게 하지만, 구현에 어려움이 있다.
  • QKD는 무조건적 보안을 제공하지만, 인프라 및 확장성 제약으로 인해 광범위한 구현에는 아직 부적합하다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.