Skip to main content
QUICK REVIEW

[论文解读] Security of Electronic Payment Systems: A Comprehensive Survey

Siamak Solat|arXiv (Cornell University)|Jan 17, 2017
Cryptography and Data Security参考文献 32被引用 15
一句话总结

本篇全面综述评估了电子支付系统的安全性,分析了实体卡(EMV)、非实体卡(3D Secure、EMV/CAP)、非接触式(NFC、Apple Pay)以及基于区块链的(比特币)系统。研究识别出关键漏洞,尤其是离线智能卡认证中的漏洞,并主张采用更强的密码学技术、令牌化、盲签名以及量子密钥分发,以实现无条件安全。

ABSTRACT

This comprehensive survey deliberated over the security of electronic payment systems. In our research, we focused on either dominant systems or new attempts and innovations to improve the level of security of the electronic payment systems. This survey consists of the Card-present (CP) transactions and a review of its dominant system i.e. EMV including several researches at Cambridge university to designate variant types of attacks against this standard which demonstrates lack of a secure "offline" authentication method that is one of the main purpose of using the smart cards instead of magnetic stripe cards which are not able to participate in authentication process, the evaluation of the EMV migration from RSA cryptosystem to ECC based cryptosystem 3. The evaluation of the Card-not-present transactions approaches including 3D Secure, 3D SET, SET/EMV and EMV/CAP, the impact of concept of Tokenization and the role of Blind Signatures schemes in electronic cash and E-payment systems, use of quantum key distribution (QKD) in electronic payment systems to achieve unconditional security rather than only computational assurance of the security level by using traditional cryptography, the evaluation of Near Field Communication (NFC) and the contactless payment systems such as Google wallet, Android Pay and Apple Pay, the assessment of the electronic currency and peer to peer payment systems such as Bitcoin. The criterion of our survey for the measurement and the judgment about the quality of the security in electronic payment systems was this quote: "The security of a system is only as strong as its weakest link"

研究动机与目标

  • 分析主流及新兴电子支付系统的安全态势。
  • 识别系统性漏洞,特别是EMV智能卡离线认证中的漏洞。
  • 评估现代协议(如3D Secure、EMV/CAP和令牌化)在缓解欺诈方面的有效性。
  • 探索先进密码学(如ECC、盲签名)和量子密钥分发在实现无条件安全方面的潜力。
  • 评估非接触式支付系统(如Apple Pay、Google Wallet)和去中心化系统(如比特币)的安全性。

提出的方法

  • 对EMV标准及剑桥大学展示的侧信道攻击进行系统性回顾。
  • 评估EMV中从RSA向ECC迁移以提升效率和安全性的效果。
  • 分析3D Secure、3D SET、SET/EMV和EMV/CAP协议在非实体卡交易中的应用。
  • 研究令牌化和盲签名方案在提升电子现金系统隐私与安全性方面的应用。
  • 探讨量子密钥分发(QKD)作为实现信息论安全的手段。
  • 评估基于NFC的非接触式支付系统(包括Apple Pay和Android Pay),重点关注威胁模型和实现缺陷。

实验结果

研究问题

  • RQ1尽管已取代磁条卡,为何EMV智能卡的离线认证机制仍是一个薄弱环节?
  • RQ23D Secure和EMV/CAP在防止非实体卡欺诈方面效果如何?
  • RQ3令牌化和盲签名在多大程度上能提升电子支付的安全性和隐私性?
  • RQ4量子密钥分发(QKD)能否为电子支付系统提供无条件安全?
  • RQ5基于NFC的非接触式支付系统(如Apple Pay和Google Wallet)存在哪些关键漏洞?

主要发现

  • EMV的离线认证机制易受侧信道攻击和故障注入攻击影响,严重削弱其核心安全目标。
  • EMV中从RSA向ECC的迁移提升了性能和安全性,但并未解决离线认证中的根本性缺陷。
  • 3D Secure和EMV/CAP协议存在可用性问题,且易受中间人攻击。
  • 令牌化显著降低了电子商务交易中卡数据泄露的风险。
  • 盲签名方案可实现隐私保护的电子现金系统,但面临部署挑战。
  • QKD可提供无条件安全,但由于基础设施和可扩展性限制,目前尚不适用于大规模部署。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。