Relay cost bounding for contactless EMV payments

T. Chothia, F.D. Garcia, J. De Ruiter, J.M. Van Den Breekel, M. Thompson

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

34 Citations (Scopus)

Abstract

This paper looks at relay attacks against contactless payment cards, which could be used to wirelessly pickpocket money from victims. We discuss the two leading contactless EMV payment protocols (Visa’s payWave and MasterCard’s PayPass). Stopping a relay attack against cards using these protocols is hard: either the overhead of the communication is low compared to the (cryptographic) computation by the card or the messages can be cached before they are requested by the terminal. We propose a solution that fits within the EMV Contactless specification to make a payment protocol that is resistant to relay attacks from commercial off-the-shelf devices, such as mobile phones. This solution does not require significant changes to the cards and can easily be added to existing terminals. To prove that our protocol really does stop relay attacks, we develop a new method of automatically checking defences against relay attacks using the applied pi-calculus and the tool ProVerif.

Original languageEnglish
Title of host publicationFinancial Cryptography and Data Security
Subtitle of host publication19th International Conference, FC 2015, San Juan, Puerto Rico, January 26-30, 2015, Revised Selected Papers
EditorsR. Böhme , T. Okamoto
Place of PublicationDordrecht
PublisherSpringer
Pages189-206
Number of pages18
ISBN (Electronic)978-3-662-47854-7
ISBN (Print)978-3-662-47853-0
DOIs
Publication statusPublished - 2015
Event19th International Conference on Financial Cryptography and Data Security (FC 2015), January 26-30, 2015, San Juan, Puderto Rico - San Juan, Puerto Rico
Duration: 26 Jan 201530 Jan 2015

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume8975
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference19th International Conference on Financial Cryptography and Data Security (FC 2015), January 26-30, 2015, San Juan, Puderto Rico
Abbreviated titleFC 2015
Country/TerritoryPuerto Rico
CitySan Juan
Period26/01/1530/01/15

Fingerprint

Dive into the research topics of 'Relay cost bounding for contactless EMV payments'. Together they form a unique fingerprint.

Cite this