EMV: Why Payment Systems Fail

被引:14
作者
Anderson, Ross [1 ]
Murdoch, Steven J. [1 ]
机构
[1] Univ Cambridge, Comp Lab, Cambridge CB2 1TN, England
关键词
D O I
10.1145/2602321
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
US credit card companies and banks are starting to distribute new credit cards with an embedded chip and magnetic strip that has been in use from the 1970s. The credit card companies and banks can learn several lessons from such efforts made in Europe. The idea behind EMV is simple enough where the card is authenticated by a chip that is more difficult to forge than the magnetic strip. Banks in the UK decided to use PIN verification wherever possible, so that the system there is branded. The US scheme is a mixture, with some banks issuing chip-and-PIN cards and others going down the signature route. EMV also introduces some new vulnerabilities, as the first-wave EMV cards in the UK have been cheap cards capable of Static Data Authentication (SDA) where the card contains a certificate signed by the bank attesting the card data is genuine.
引用
收藏
页码:24 / 28
页数:5
相关论文
共 5 条
[1]  
Bond M., 2014, P IEEE S SEC PRIV SA
[2]  
Drimer S., 2007, P USENIX SEC S BOST
[3]  
Drimer S., 2008, P IEEE S SEC PRIV OA
[4]  
Murdoch S.J., 2010, P IEEE S SEC PRIV OA
[5]  
Murdoch S.J., 2014, P FIN CRYPT DAT SEC