Skip to main content
QUICK REVIEW

[Paper Review] Security of Electronic Payment Systems: A Comprehensive Survey

Siamak Solat|arXiv (Cornell University)|Jan 17, 2017
Cryptography and Data Security32 references15 citations
TL;DR

This comprehensive survey evaluates the security of electronic payment systems, analyzing card-present (EMV), card-not-present (3D Secure, EMV/CAP), contactless (NFC, Apple Pay), and blockchain-based (Bitcoin) systems. It identifies critical vulnerabilities—especially in offline smart card authentication—and advocates for stronger cryptography, tokenization, blind signatures, and quantum key distribution to achieve unconditional security.

ABSTRACT

This comprehensive survey deliberated over the security of electronic payment systems. In our research, we focused on either dominant systems or new attempts and innovations to improve the level of security of the electronic payment systems. This survey consists of the Card-present (CP) transactions and a review of its dominant system i.e. EMV including several researches at Cambridge university to designate variant types of attacks against this standard which demonstrates lack of a secure "offline" authentication method that is one of the main purpose of using the smart cards instead of magnetic stripe cards which are not able to participate in authentication process, the evaluation of the EMV migration from RSA cryptosystem to ECC based cryptosystem 3. The evaluation of the Card-not-present transactions approaches including 3D Secure, 3D SET, SET/EMV and EMV/CAP, the impact of concept of Tokenization and the role of Blind Signatures schemes in electronic cash and E-payment systems, use of quantum key distribution (QKD) in electronic payment systems to achieve unconditional security rather than only computational assurance of the security level by using traditional cryptography, the evaluation of Near Field Communication (NFC) and the contactless payment systems such as Google wallet, Android Pay and Apple Pay, the assessment of the electronic currency and peer to peer payment systems such as Bitcoin. The criterion of our survey for the measurement and the judgment about the quality of the security in electronic payment systems was this quote: "The security of a system is only as strong as its weakest link"

Motivation & Objective

  • To analyze the security posture of dominant and emerging electronic payment systems.
  • To identify systemic vulnerabilities, particularly in offline authentication of EMV smart cards.
  • To evaluate the effectiveness of modern protocols like 3D Secure, EMV/CAP, and tokenization in mitigating fraud.
  • To explore the potential of advanced cryptography (e.g., ECC, blind signatures) and quantum key distribution for achieving unconditional security.
  • To assess the security of contactless payment systems (e.g., Apple Pay, Google Wallet) and decentralized systems like Bitcoin.

Proposed method

  • Systematic review of EMV standards and side-channel attacks demonstrated at Cambridge University.
  • Evaluation of the transition from RSA to ECC in EMV for improved efficiency and security.
  • Analysis of 3D Secure, 3D SET, SET/EMV, and EMV/CAP protocols for card-not-present transactions.
  • Examination of tokenization and blind signature schemes in enhancing privacy and security in electronic cash systems.
  • Investigation of quantum key distribution (QKD) as a means to achieve information-theoretic security.
  • Assessment of NFC-based contactless payment systems, including Apple Pay and Android Pay, focusing on threat models and implementation flaws.

Experimental results

Research questions

  • RQ1Why is offline authentication in EMV smart cards still a weak link despite replacing magnetic stripes?
  • RQ2How effective are 3D Secure and EMV/CAP in preventing card-not-present fraud?
  • RQ3To what extent can tokenization and blind signatures improve the security and privacy of electronic payments?
  • RQ4Can quantum key distribution (QKD) provide unconditional security in electronic payment systems?
  • RQ5What are the critical vulnerabilities in NFC-based contactless payment systems like Apple Pay and Google Wallet?

Key findings

  • EMV’s offline authentication mechanism is vulnerable to side-channel and fault injection attacks, undermining its primary security goal.
  • The migration from RSA to ECC in EMV improves performance and security, but does not resolve fundamental flaws in offline authentication.
  • 3D Secure and EMV/CAP protocols suffer from usability issues and are susceptible to man-in-the-middle attacks.
  • Tokenization significantly reduces the risk of card data exposure in e-commerce transactions.
  • Blind signature schemes enable privacy-preserving electronic cash systems but face deployment challenges.
  • QKD offers unconditional security but remains impractical for widespread deployment due to infrastructure and scalability constraints.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.