Who Pays Whom? Anonymous EMV-Compliant Contactless Payments

Tom Chothia, Anna Clee, Ioana Boureanu, Christopher J.P. Newton, Liqun Chen, Andreas Kokkinis, Charles Olivier-Anclin, Pascal Lafourcade

Research output: Chapter in Book/Report/Conference proceedingConference contribution

10 Downloads (Pure)

Abstract

EMV is the de-facto worldwide payment system used by Mastercard, Visa, American Express, and such. In-shop EMV contactless payments are not anonymous or private: the payers' long-term identification data leaks to merchants or even to observers. Anti-Money Laundering (AML), Know Your Customer (KYC) and Strong Customer Authentication (SCA) are payment regulations protecting us from illegal activities, but --in so doing-- contribute chiefly to this lack of privacy in EMV payments. Threading the tightrope of AML, KYC and SCA regulations, we provide two privacy-enhancing, EMV-compatible, law-abiding and usable and practicable contactless-payments protocols: PrivBank and PrivProxy. We do not use privacy-enhancing technology, like homomorphic encryption, that would break backwards-compatibility with current EMV, but rather we do privacy by engineering design, adhering to the existing EMV infrastructure, as is. So, PrivBank and PrivProxy provably achieve strong notions of payers and merchant privacy, anonymity and unlinkability as seen in e-cash or shopping vouchers, whilst being implementable in EMV as it stands.
Original languageEnglish
Title of host publicationUSENIX Security '25
PublisherUSENIX Association
Publication statusAccepted/In press - 31 Jan 2025
Event34th USENIX Security Symposium - Seattle Convention Center, Seattle, United States
Duration: 13 Aug 202515 Aug 2025
https://www.usenix.org/conference/usenixsecurity25

Publication series

NameUSENIX Conference Proceedings
PublisherUSENIX Association
ISSN (Print)1049-5606

Conference

Conference34th USENIX Security Symposium
Abbreviated titleUSENIX Security '25
Country/TerritoryUnited States
CitySeattle
Period13/08/2515/08/25
Internet address

Bibliographical note

Not yet published as of 09/07/2025.

Fingerprint

Dive into the research topics of 'Who Pays Whom? Anonymous EMV-Compliant Contactless Payments'. Together they form a unique fingerprint.

Cite this