TY - JOUR
T1 - Eavesdropping of Magnetic Secure Transmission Signals and Its Security Implications for a Mobile Payment Protocol
AU - Choi, Daeseon
AU - Lee, Younho
N1 - Publisher Copyright:
© 2013 IEEE.
PY - 2018/7/25
Y1 - 2018/7/25
N2 - Magnetic secure transmission (MST) is a technology that emulates the action of swiping a magstripe card in a card reader in that it artificially generates the magnetic signal produced when a card is swiped. MST provides extremely high backward compatibility, i.e., mobile payment using an MST device is possible through most conventional magstripe readers. However, MST devices transmit magnetic signals to a remote magstripe card reader. Hence, it is possible to eavesdrop on such signals. We developed a device that can remotely eavesdrop on magnetic signals emitted by MST devices. Thus, we could obtain the one-time payment token contained in such signals at a maximum distance of 2.7 m. We successfully performed a wormhole attack against Samsung Pay, a widely used MST-based mobile payment service, and we were able to execute payment a few kilometers from where the eavesdropped one-time token was actually created.
AB - Magnetic secure transmission (MST) is a technology that emulates the action of swiping a magstripe card in a card reader in that it artificially generates the magnetic signal produced when a card is swiped. MST provides extremely high backward compatibility, i.e., mobile payment using an MST device is possible through most conventional magstripe readers. However, MST devices transmit magnetic signals to a remote magstripe card reader. Hence, it is possible to eavesdrop on such signals. We developed a device that can remotely eavesdrop on magnetic signals emitted by MST devices. Thus, we could obtain the one-time payment token contained in such signals at a maximum distance of 2.7 m. We successfully performed a wormhole attack against Samsung Pay, a widely used MST-based mobile payment service, and we were able to execute payment a few kilometers from where the eavesdropped one-time token was actually created.
KW - Magnetic secure transmission
KW - mobile security
KW - Samsung pay
KW - security
UR - https://www.scopus.com/pages/publications/85050609203
U2 - 10.1109/ACCESS.2018.2859447
DO - 10.1109/ACCESS.2018.2859447
M3 - Article
AN - SCOPUS:85050609203
SN - 2169-3536
VL - 6
SP - 42687
EP - 42701
JO - IEEE Access
JF - IEEE Access
M1 - 8419696
ER -