Risks of offline verify PIN on contactless cards

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Contactless card payments are being introduced around the world allowing customers to use a card to pay for small purchases by simply placing the card onto the Point of Sale terminal. Contactless transactions do not require verification of the cardholder's PIN. However our research has found the redundant verify PIN functionality is present on the most commonly issued contactless credit and debit cards currently in circulation in the UK. This paper presents a plausible attack scenario which exploits contactless verify PIN to give unlimited attempts to guess the cardholder's PIN without their knowledge. It also gives experimental data to demonstrate the practical viability of the attack as well as references to support our argument that contactless verify PIN is redundant functionality which compromises the security of payment cards and the cardholder.

Original languageEnglish
Title of host publicationFinancial Cryptography and Data Security - 17th International Conference, FC 2013, Revised Selected Papers
Pages313-321
Number of pages9
DOIs
Publication statusPublished - 2013
Event17th International Conference on Financial Cryptography and Data Security, FC 2013 - Okinawa, Japan
Duration: 1 Apr 20135 Apr 2013

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume7859 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference17th International Conference on Financial Cryptography and Data Security, FC 2013
Country/TerritoryJapan
CityOkinawa
Period1/04/135/04/13

Keywords

  • Card Payment
  • Chip & PIN
  • Contactless Payments
  • Credit Card
  • Debit Card
  • EMV
  • NFC
  • Verify PIN

ASJC Scopus subject areas

  • Theoretical Computer Science
  • General Computer Science

Fingerprint

Dive into the research topics of 'Risks of offline verify PIN on contactless cards'. Together they form a unique fingerprint.

Cite this