240

SoK: Attacks on Modern Card Payments

Main:27 Pages
10 Figures
Bibliography:4 Pages
3 Tables
Appendix:6 Pages
Abstract

EMV is the global standard for smart card payments and its NFC-based version, EMV contactless, is widely used, also for mobile payments. In this systematization of knowledge, we examine attacks on the EMV contactless protocol. We provide a comprehensive framework encompassing its desired security properties and adversary models. We also identify and categorize a comprehensive collection of protocol flaws and show how different subsets thereof can be combined into attacks. In addition to this systematization, we examine the underlying reasons for the many attacks against EMV and point to a better way forward.

View on arXiv
Comments on this paper