Over the past decade, smartphones have become the point of convergence for many applications and services. There is a growing trend in which traditional smart-card based services like banking, transport and access control are being provisioned through smartphones. Smartphones with Near Field Communication (NFC) capability can emulate a contactless smart card; popular examples of such services include Google Pay and Apple Pay. Similar to contactless smart cards, NFC-based smartphone transactions are susceptible to relay attacks. For contactless smart cards, distance-bounding protocols are proposed to counter such attacks; for NFC-based smartphone transactions, ambient sensors have been proposed as potential countermeasures. In this study, we have empirically evaluated the suitability of ambient sensors as a proximity detection mechanism for contactless transactions. To provide a comprehensive analysis, we also collected relay attack data to ascertain whether ambient sensors are able to thwart such attacks effectively. We initially evaluated 17 sensors before selecting 7 sensors for in-depth analysis based on their effectiveness as potential proximity detection mechanisms within the constraints of a contactless transaction scenario. Each sensor was used to record 1000 legitimate and relay (illegitimate) contactless transactions at four different physical locations. The analysis of these transactions provides an empirical foundation on which to determine whether ambient sensors provide a strong proximity detection mechanism for security-sensitive applications like banking, transport and high-security access control.
翻译:过去十年来,智能手机已成为许多应用和服务的共同点; 银行、运输和出入控制等传统的智能卡服务正在通过智能手机提供; 使用近地通信(NFC)的智能手机能力可以模仿无接触智能卡; 此类服务的流行范例包括谷歌付费和苹果付费; 类似无接触智能卡,基于NFC的智能手机交易容易中继攻击; 对于无接触智能卡,提议远程连接协议,以对抗这种攻击; 对于基于NFC的智能电话交易,环境传感器被提议为潜在的对策; 在本研究中,我们对环境传感器是否适合作为无接触交易的近距离探测机制进行了实证性评估; 为了提供全面分析,我们还收集了中继攻击数据,以确定环境传感器是否能够有效地挫败这种攻击; 我们先对17个传感器进行了初步评估,然后根据它们作为无接触交易的制约下的潜在近距离探测机制来进行深入分析; 对于以NFCFC为基础的智能电话交易, 环境传感器被提议作为潜在的对策; 环境传感器被提议为潜在的对策。 在本研究中,我们从经验上评估了环境传感器是否适合环境传感器作为无接触的近距离检测机制; 为了确定四个不同实体的高度安全控制地点的高度安全控制,这些系统,对这些交易进行分析。