[论文解读] Analysis of Applicability of ISO 9564 PIN based Authentication to Closed-Loop Mobile Payment Systems
本文批判性地评估了ISO 9564基于PIN的认证在封闭式移动支付系统中的适用性。尽管ISO 9564提供了强大的认证原则,但其在移动环境中的直接采用存在问题,原因在于威胁模型和系统约束存在差异,因此呼吁通过CCRA或类似标准机构制定一种与移动设备无关的保护配置文件,以解决封闭式移动支付的独特安全需求。
Payment transactions initiated through a mobile device are growing and security concerns must be ad-dressed. People coming from payment card industry often talk passionately about porting ISO 9564 PIN standard based authentication in open-loop card payment to closed-loop mobile financial transactions and certification of closed-loop payment product or solution against this standard. In reality, so far this standard has not been adopted in closed-loop mobile payment authentication and applicability of this ISO standard must be studied carefully before adoption. The authors do a critical analysis of the applicability of this ISO specification and makes categorical statement about relevance of compliance to closed-loop mobile payment. Security requirements for authentication in closed-loop mobile payment systems are not standardized through ISO 9564 standard, Common Criteria, etc. Since closed-loop mobile payment is a relatively new field, the authors make a case for Common Criteria Recognition Agreement (CCRA) or other standards organization to push for publication of a mobile device-agnostic Protection Profile or standard for it, incorporating the suggested authentication approaches.
研究动机与目标
- 评估ISO 9564基于PIN的认证是否适用于封闭式移动支付系统。
- 识别开放式卡片系统与封闭式移动环境之间在安全性和架构上的不匹配之处。
- 强调当前封闭式移动支付系统在认证方面缺乏标准化的安全要求。
- 倡导通过CCRA等标准组织制定与移动设备无关的保护配置文件。
- 推动制定一种量身定制的标准,整合强大且面向移动设备的认证方法。
提出的方法
- 对ISO 9564在传统支付卡中的设计与基于移动设备的封闭式系统运行环境进行对比分析。
- 评估开放式与封闭式移动支付生态系统之间威胁模型的差异。
- 检查移动设备的技术和部署约束,例如输入方式受限以及信任模型的差异。
- 审查现有标准(如通用准则)并识别其在仅限移动支付系统中的适用性差距。
- 提出一种新框架,用于制定包含安全PIN处理和设备特定信任机制的、与移动设备无关的保护配置文件。
- 通过威胁建模和合规性分析,评估在移动环境中采用ISO 9564的可行性和风险。
实验结果
研究问题
- RQ1ISO 9564基于PIN的认证能否在封闭式移动支付系统中有效且安全地应用?
- RQ2开放式卡片系统与封闭式移动支付系统在架构和威胁模型上的关键差异是什么,这些差异如何影响认证设计?
- RQ3尽管行业有倡导,为何ISO 9564仍未被应用于封闭式移动支付解决方案?
- RQ4当前标准在仅限移动支付的认证方面缺少哪些关键安全要求?
- RQ5CCRA等标准组织在为封闭式移动支付制定新的、与移动设备无关的安全标准方面应发挥什么作用?
主要发现
- 由于威胁模型和部署环境的根本差异,ISO 9564不适用于封闭式移动支付系统。
- 移动支付认证缺乏标准化安全要求,导致信任和合规性方面存在显著缺口。
- 移动设备带来了独特的挑战,如输入安全性有限和动态信任边界,而ISO 9564未能充分应对这些问题。
- 在未进行重大调整和威胁建模的情况下,不建议直接对封闭式移动解决方案进行ISO 9564认证。
- 迫切需要制定一种新的、与移动设备无关的保护配置文件,以标准化封闭式移动支付中的安全认证。
- 作者建议CCRA等标准组织优先推动此类配置文件的开发,以确保长期安全性和互操作性。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。