Skip to main content
QUICK REVIEW

[论文解读] Survey of Strong Authentication Approaches for Mobile Proximity and Remote Wallet Applications - Challenges and Evolution

Amal Saha, Sugata Sanyal|arXiv (Cornell University)|Dec 9, 2014
User Authentication and Security Systems参考文献 2被引用 3
一句话总结

本文综述了移动近场与远程钱包应用中的强认证方法,分析了现有方法的挑战及向设备指纹识别和EMVCo令牌化演进的趋势。本文提出,基于上下文的多因素认证(利用设备属性)将保持主导地位,未来令牌系统很可能需要设备指纹识别以实现强认证。

ABSTRACT

Wallet may be described as container application used for configuring, accessing and analysing data from underlying payment application(s). There are two dominant types of digital wallet applications, proximity wallet and remote wallet. In the payment industry, one often hears about authentication approach for proximity or remote wallets or the underlying payment applications separately, but there is no such approach, as per our knowledge, for combined wallet, the holder application. While Secure Element (SE) controlled by the mobile network operator (i.e., SIM card) may ensure strong authentication, it introduces strong dependencies among business partners in payments and hence is not getting fraction. Embedded SE in the form of trusted execution environment [3, 4, 5] or trusted computing [24] may address this issue in future. But such devices tend to be a bit expensive and are not abundant in the market. Meanwhile, for many years, context based authentication involving device fingerprinting and other contextual information for conditional multi-factor authentication, would prevail and would remain as the most dominant and strong authentication mechanism for mobile devices from various vendors in different capability and price ranges. EMVCo payment token standard published in 2014 tries to address security of wallet based payment in a general way. The authors believe that it is quite likely that EMVCo payment token implementations would evolve in course of time in such a way that token service providers would start insisting on device fingerprinting as strong means of authentication before issuing one-time-use payment token. This paper talks about challenges of existing authentication mechanisms used in payment and wallet applications, and their evolution.

研究动机与目标

  • 分析移动近场与远程钱包应用中强认证的挑战。
  • 审视现有认证机制的局限性,包括对基于SIM卡的安全元件的依赖。
  • 探讨认证方法向设备指纹识别和上下文多因素方法演进的过程。
  • 评估新兴标准(如EMVCo支付令牌化)在塑造未来认证实践中的作用。
  • 识别从依赖硬件的认证向多样化移动设备生态系统中软件驱动的强认证的转变。

提出的方法

  • 调查移动钱包应用中现有认证机制,重点关注近场与远程钱包。
  • 评估安全元件(SE)和可信执行环境(TEE)在实现强认证中的作用。
  • 分析基于SIM卡的SE因供应商和运营商依赖而带来的局限性。
  • 研究基于设备指纹识别和上下文信号的上下文认证作为主导替代方案。
  • 考察EMVCo支付令牌标准(2014年)作为通用钱包安全框架的作用。
  • 预测未来趋势:令牌服务提供商可能在发放一次性使用令牌前要求进行设备指纹识别。

实验结果

研究问题

  • RQ1在移动近场与远程钱包中实现强认证的主要挑战是什么?
  • RQ2基于硬件的解决方案(如基于SIM卡的安全元件)如何影响互操作性与市场采用?
  • RQ3为何设备指纹识别预计将成为多样化移动设备生态系统中的主导认证机制?
  • RQ4EMVCo支付令牌标准在哪些方面可能演进以整合设备级认证?
  • RQ5从运营商控制的安全元件转向基于软件的可信环境,对钱包安全有何影响?

主要发现

  • 基于SIM卡的安全元件可提供强认证,但会引入支付合作伙伴间的强依赖关系,限制了广泛采用。
  • 通过TEE或可信计算实现的嵌入式安全元件为未来发展提供了有前景的路径,但成本较高,尚未广泛普及。
  • 设备指纹识别结合上下文信息预计将成为多样化、低成本移动设备上主要的强认证机制。
  • EMVCo支付令牌标准(2014年)为基于钱包的支付提供了通用安全框架,未来具有演进潜力。
  • 令牌服务提供商很可能将设备指纹识别作为发放一次性使用支付令牌的前提条件。
  • 从以硬件为中心的认证向基于软件的认证转变,主要由可扩展性、成本降低和更广泛的设备兼容性需求所驱动。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。