A relay attack for host-based card emulation (HCE) using NFC-enabled device for mobile payment

Near field communication (NFC) is a family of radio frequency identification (RFID) that used wireless communication and it becomes more popular nowadays. It has been used in many different systems such as contactless payment processing, access control, passport identification, etc. With a card...

Full description

Saved in:
Bibliographic Details
Main Author: Che Hasan, Hafizah
Format: Thesis
Language:English
Published: 2018
Subjects:
Online Access:http://psasir.upm.edu.my/id/eprint/69015/1/FSKTM%202018%2047%20-%20IR.pdf
Tags: Add Tag
No Tags, Be the first to tag this record!
id my-upm-ir.69015
record_format uketd_dc
spelling my-upm-ir.690152019-06-17T01:57:33Z A relay attack for host-based card emulation (HCE) using NFC-enabled device for mobile payment 2018-06 Che Hasan, Hafizah Near field communication (NFC) is a family of radio frequency identification (RFID) that used wireless communication and it becomes more popular nowadays. It has been used in many different systems such as contactless payment processing, access control, passport identification, etc. With a card emulation mode, NFC technology is able to emulate the smartcard such as a credit card and save it in mobile phone. Therefore, the physical credit card is no longer needed in order to perform the electronic transaction. However, NFC is susceptible to some attacks such as data fabrication and eavesdropping. Thus, the mobile payment that used the NFC technology is also at risk. NFC is also particularly vulnerable to a relay attack. A relay attack is a type of Man-In-The-Middle attack that extends the range of NFC communication. It is therefore allows an attacker to interact with a Point of Sales (PoS) using the contactless card and perform electronic transaction without a user knowledge. Attacker starts an interaction with a card reader (PoS terminal) and victim’s device through an Internet or Bluetooth connection. One type of NFC approach, which is host card emulation (HCE) approach makes a relay attacks in NFC communication becomes easier, as it could interact with PoS directly without the need to interact with Secure Element (SE) as hardware on the device. One of the objectives of this research is to identify security problem of a relay attack for HCE approach in NFC-enabled device. Thus, a proof of concept has been built and tested in a lab environment to prove that a HCE approach is susceptible to the relay attack. The result from this research shows that HCE implementation approach is susceptible to relay attack. An overview of security issues in NFC communication, the relay attack process in detail, discussion of testing result, and some mitigation techniques towards the relay attack for HCE approach on NFC-enabled device are the elements that have been discussed in this project. Mobile communication systems Radio frequency identification systems - Security measures 2018-06 Thesis http://psasir.upm.edu.my/id/eprint/69015/ http://psasir.upm.edu.my/id/eprint/69015/1/FSKTM%202018%2047%20-%20IR.pdf text en public masters Universiti Putra Malaysia Mobile communication systems Radio frequency identification systems - Security measures
institution Universiti Putra Malaysia
collection PSAS Institutional Repository
language English
topic Mobile communication systems
Radio frequency identification systems - Security measures

spellingShingle Mobile communication systems
Radio frequency identification systems - Security measures

Che Hasan, Hafizah
A relay attack for host-based card emulation (HCE) using NFC-enabled device for mobile payment
description Near field communication (NFC) is a family of radio frequency identification (RFID) that used wireless communication and it becomes more popular nowadays. It has been used in many different systems such as contactless payment processing, access control, passport identification, etc. With a card emulation mode, NFC technology is able to emulate the smartcard such as a credit card and save it in mobile phone. Therefore, the physical credit card is no longer needed in order to perform the electronic transaction. However, NFC is susceptible to some attacks such as data fabrication and eavesdropping. Thus, the mobile payment that used the NFC technology is also at risk. NFC is also particularly vulnerable to a relay attack. A relay attack is a type of Man-In-The-Middle attack that extends the range of NFC communication. It is therefore allows an attacker to interact with a Point of Sales (PoS) using the contactless card and perform electronic transaction without a user knowledge. Attacker starts an interaction with a card reader (PoS terminal) and victim’s device through an Internet or Bluetooth connection. One type of NFC approach, which is host card emulation (HCE) approach makes a relay attacks in NFC communication becomes easier, as it could interact with PoS directly without the need to interact with Secure Element (SE) as hardware on the device. One of the objectives of this research is to identify security problem of a relay attack for HCE approach in NFC-enabled device. Thus, a proof of concept has been built and tested in a lab environment to prove that a HCE approach is susceptible to the relay attack. The result from this research shows that HCE implementation approach is susceptible to relay attack. An overview of security issues in NFC communication, the relay attack process in detail, discussion of testing result, and some mitigation techniques towards the relay attack for HCE approach on NFC-enabled device are the elements that have been discussed in this project.
format Thesis
qualification_level Master's degree
author Che Hasan, Hafizah
author_facet Che Hasan, Hafizah
author_sort Che Hasan, Hafizah
title A relay attack for host-based card emulation (HCE) using NFC-enabled device for mobile payment
title_short A relay attack for host-based card emulation (HCE) using NFC-enabled device for mobile payment
title_full A relay attack for host-based card emulation (HCE) using NFC-enabled device for mobile payment
title_fullStr A relay attack for host-based card emulation (HCE) using NFC-enabled device for mobile payment
title_full_unstemmed A relay attack for host-based card emulation (HCE) using NFC-enabled device for mobile payment
title_sort relay attack for host-based card emulation (hce) using nfc-enabled device for mobile payment
granting_institution Universiti Putra Malaysia
publishDate 2018
url http://psasir.upm.edu.my/id/eprint/69015/1/FSKTM%202018%2047%20-%20IR.pdf
_version_ 1747812657719672832