Skip to main content
QUICK REVIEW

[논문 리뷰] Survey of Strong Authentication Approaches for Mobile Proximity and Remote Wallet Applications - Challenges and Evolution

Amal Saha, Sugata Sanyal|arXiv (Cornell University)|2014. 12. 09.
User Authentication and Security Systems참고 문헌 2인용 수 3
한 줄 요약

이 논문은 모바일 프록시티 및 원격 월렛 애플리케이션을 위한 강력한 인증 방법을 조사하며, 기존 방법의 과제를 분석하고 디바이스 지문 기반 및 EMVCo 토큰화로의 진화를 다룬다. 기술적 특성 기반의 다중 요인 인증이 향후에도 주도적일 것으로 예측되며, 향후 토큰 시스템은 강력한 인증을 위해 디바이스 지문 기반 기술을 요구할 가능성이 높다.

ABSTRACT

Wallet may be described as container application used for configuring, accessing and analysing data from underlying payment application(s). There are two dominant types of digital wallet applications, proximity wallet and remote wallet. In the payment industry, one often hears about authentication approach for proximity or remote wallets or the underlying payment applications separately, but there is no such approach, as per our knowledge, for combined wallet, the holder application. While Secure Element (SE) controlled by the mobile network operator (i.e., SIM card) may ensure strong authentication, it introduces strong dependencies among business partners in payments and hence is not getting fraction. Embedded SE in the form of trusted execution environment [3, 4, 5] or trusted computing [24] may address this issue in future. But such devices tend to be a bit expensive and are not abundant in the market. Meanwhile, for many years, context based authentication involving device fingerprinting and other contextual information for conditional multi-factor authentication, would prevail and would remain as the most dominant and strong authentication mechanism for mobile devices from various vendors in different capability and price ranges. EMVCo payment token standard published in 2014 tries to address security of wallet based payment in a general way. The authors believe that it is quite likely that EMVCo payment token implementations would evolve in course of time in such a way that token service providers would start insisting on device fingerprinting as strong means of authentication before issuing one-time-use payment token. This paper talks about challenges of existing authentication mechanisms used in payment and wallet applications, and their evolution.

연구 동기 및 목표

  • 모바일 프록시티 및 원격 월렛 애플리케이션을 위한 강력한 인증의 과제를 분석하기 위해.
  • SIM 기반 세이프티 엘리먼트에 의존하는 기존 인증 메커니즘의 한계를 검토하기 위해.
  • 디바이스 지문 기반 및 맥락 기반 다중 요인 방법으로의 인증 진화를 탐색하기 위해.
  • 미래의 인증 관행을 형성하는 데 기여할 수 있는 새로운 표준, 예를 들어 EMVCo 결제 토큰화의 역할을 평가하기 위해.
  • 다양한 모바일 디바이스 생태계에서 하드웨어 기반에서 소프트웨어 기반 강력한 인증으로의 전환을 규명하기 위해.

제안 방법

  • 프록시티 및 원격 월렛에 중점을 두어 기존의 모바일 월렛 애플리케이션 내 인증 메커니즘을 조사하기 위해.
  • 강력한 인증을 가능하게 하는 세이프티 엘리먼트(SE)와 트러스트드 엑스큐션 환경(TEE)의 역할을 평가하기 위해.
  • 벤더 및 통신사 의존성으로 인해 SIM 기반 SE의 한계를 분석하기 위해.
  • 디바이스 지문 기반 및 맥락 신호를 활용한 맥락 기반 인증이 주요 대안으로 부상하는 과정을 조사하기 위해.
  • 일반적인 월렛 보안을 위한 프레임워크로서의 EMVCo 결제 토큰 표준(2014)을 분석하기 위해.
  • 향후 추세로, 토큰 서비스 제공자가 일회용 사용 토큰을 발행하기 전에 디바이스 지문 기반 기술을 요구할 가능성을 예측하기 위해.

실험 결과

연구 질문

  • RQ1모바일 프록시티 및 원격 월렛을 위한 강력한 인증을 구현하는 데 있어 주요 과제는 무엇인가요?
  • RQ2SIM 기반 세이프티 엘리먼트와 같은 하드웨어 기반 솔루션은 상호운용성과 시장 보급에 어떤 영향을 미치나요?
  • RQ3왜 다양한 모바일 디바이스 생태계에서 디바이스 지문 기반 기술이 주요 인증 수단으로 부상할 것으로 기대되나요?
  • RQ4EMVCo 결제 토큰 표준은 디바이스 수준의 인증을 통합하기 위해 어떻게 진화할 수 있나요?
  • RQ5통신사가 제어하는 SE에서 소프트웨어 기반 트러스트드 환경으로의 전환은 월렛 보안에 어떤 영향을 미치나요?

주요 결과

  • SIM 기반 세이프티 엘리먼트는 강력한 인증을 제공하지만, 결제 파artner 간 강력한 의존성을 유도하여 광범위한 보급을 제한한다.
  • TEE 또는 트러스트드 컴퓨팅을 통한 임베디드 세이프티 엘리먼트는 유망한 미래 방향성을 보이지만, 여전히 비용이 높고 널리 보급되지 않은 상태이다.
  • 디바이스 지문 기반 기술과 맥락 정보의 조합은 다양한 저가형 모바일 디바이스에서 주요 강력한 인증 수단으로 자리 잡을 것으로 기대된다.
  • EMVCo 결제 토큰 표준(2014)은 월렛 기반 결제를 위한 일반적인 보안 프레임워크를 제공하며, 향후 진화 가능성이 있다.
  • 토큰 서비스 제공자가 일회용 사용 토큰을 발행하기 전에 디바이스 지문 기반 기술을 사전 조건으로 요구할 가능성이 점점 커지고 있다.
  • 하드웨어 중심에서 소프트웨어 중심의 인증으로의 전환은 확장성 향상, 비용 절감, 그리고 더 넓은 디바이스 호환성 확보의 필요성에서 비롯된다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.