Skip to main content
QUICK REVIEW

[Paper Review] Survey of Strong Authentication Approaches for Mobile Proximity and Remote Wallet Applications - Challenges and Evolution

Amal Saha, Sugata Sanyal|arXiv (Cornell University)|Dec 9, 2014
User Authentication and Security Systems2 references3 citations
TL;DR

This paper surveys strong authentication approaches for mobile proximity and remote wallet applications, analyzing challenges in existing methods and the evolution toward device fingerprinting and EMVCo tokenization. It proposes that context-based multi-factor authentication using device attributes will remain dominant, with future token systems likely requiring device fingerprinting for strong authentication.

ABSTRACT

Wallet may be described as container application used for configuring, accessing and analysing data from underlying payment application(s). There are two dominant types of digital wallet applications, proximity wallet and remote wallet. In the payment industry, one often hears about authentication approach for proximity or remote wallets or the underlying payment applications separately, but there is no such approach, as per our knowledge, for combined wallet, the holder application. While Secure Element (SE) controlled by the mobile network operator (i.e., SIM card) may ensure strong authentication, it introduces strong dependencies among business partners in payments and hence is not getting fraction. Embedded SE in the form of trusted execution environment [3, 4, 5] or trusted computing [24] may address this issue in future. But such devices tend to be a bit expensive and are not abundant in the market. Meanwhile, for many years, context based authentication involving device fingerprinting and other contextual information for conditional multi-factor authentication, would prevail and would remain as the most dominant and strong authentication mechanism for mobile devices from various vendors in different capability and price ranges. EMVCo payment token standard published in 2014 tries to address security of wallet based payment in a general way. The authors believe that it is quite likely that EMVCo payment token implementations would evolve in course of time in such a way that token service providers would start insisting on device fingerprinting as strong means of authentication before issuing one-time-use payment token. This paper talks about challenges of existing authentication mechanisms used in payment and wallet applications, and their evolution.

Motivation & Objective

  • To analyze the challenges in strong authentication for mobile proximity and remote wallet applications.
  • To examine the limitations of existing authentication mechanisms, including reliance on SIM-based Secure Elements.
  • To explore the evolution of authentication toward device fingerprinting and contextual multi-factor methods.
  • To assess the role of emerging standards like EMVCo payment tokenization in shaping future authentication practices.
  • To identify the shift from hardware-dependent to software-based strong authentication in diverse mobile device ecosystems.

Proposed method

  • Surveying existing authentication mechanisms in mobile wallet applications, focusing on proximity and remote wallets.
  • Evaluating the role of Secure Elements (SE) and Trusted Execution Environments (TEE) in enabling strong authentication.
  • Analyzing the limitations of SIM-based SE due to vendor and operator dependencies.
  • Investigating context-based authentication using device fingerprinting and contextual signals as a dominant alternative.
  • Examining the EMVCo payment token standard (2014) as a framework for general-purpose wallet security.
  • Projecting future trends where token service providers may require device fingerprinting before issuing one-time-use tokens.

Experimental results

Research questions

  • RQ1What are the primary challenges in implementing strong authentication for mobile proximity and remote wallets?
  • RQ2How do hardware-based solutions like SIM-based Secure Elements affect interoperability and market adoption?
  • RQ3Why is device fingerprinting expected to become the dominant authentication mechanism in diverse mobile device ecosystems?
  • RQ4In what ways might the EMVCo payment token standard evolve to incorporate device-level authentication?
  • RQ5What are the implications of shifting from operator-controlled SE to software-based trusted environments for wallet security?

Key findings

  • SIM-based Secure Elements provide strong authentication but introduce strong dependencies among payment partners, limiting widespread adoption.
  • Embedded Secure Elements via TEE or trusted computing offer a promising future path but remain costly and not yet widely available.
  • Device fingerprinting combined with contextual information is expected to dominate as the primary strong authentication mechanism across diverse, low-cost mobile devices.
  • The EMVCo payment token standard (2014) provides a general security framework for wallet-based payments, with potential for future evolution.
  • There is a growing likelihood that token service providers will require device fingerprinting as a prerequisite for issuing one-time-use payment tokens.
  • The shift from hardware-centric to software-based authentication is driven by the need for scalability, cost reduction, and broader device compatibility.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.