More is Less: Extra Features in Contactless Payments Break Security

Tom Chothia, Anna Clee, Ioana Boureanu, George Pavlides

Research output: Chapter in Book/Report/Conference proceedingConference contribution

118 Downloads (Pure)

Abstract

The EMV contactless payment system has many independent parties: payment providers, smartphone companies, banks and regulators. EMVCo publishes a 15 book specification that these companies use to operate together. However, many of these parties have independently added additional features, such as Square restricting offline readers to phone transactions only, Apple, Google and Samsung implementing transit modes and Visa and Mastercard complying with regional regulations on high value contactless payments. We investigate these features and find that these parties have been independently retrofitting and overloading the core EMV specification. Subtle interactions and mismatches between the different companies' additions lead to a range of vulnerabilities, making it possible to bypass restrictions to smartphone only payments, make unauthenticated high value transactions offline, and use a cloned card to make a £25000 transaction offline. To find fixes, we build formal models of the EMV protocol with the new features we investigated and test different possible solutions. We have engaged with EMV stakeholders and worked with the company Square to implement these fixes.
Original languageEnglish
Title of host publicationUSENIX Security '25
PublisherUSENIX Association
Publication statusAccepted/In press - 31 Jan 2025
Event34th USENIX Security Symposium - Seattle Convention Center, Seattle, United States
Duration: 13 Aug 202515 Aug 2025
https://www.usenix.org/conference/usenixsecurity25

Publication series

NameUSENIX Conference Proceedings
PublisherUSENIX Association
ISSN (Print)1049-5606

Conference

Conference34th USENIX Security Symposium
Abbreviated titleUSENIX Security '25
Country/TerritoryUnited States
CitySeattle
Period13/08/2515/08/25
Internet address

Bibliographical note

Not yet published as of 09/07/2025.

Fingerprint

Dive into the research topics of 'More is Less: Extra Features in Contactless Payments Break Security'. Together they form a unique fingerprint.

Cite this