首页> 外文会议>Financial cryptography and data security >Optimised to Fail: Card Readers for Online Banking
【24h】

Optimised to Fail: Card Readers for Online Banking

机译:优化失败:用于在线银行的读卡器

获取原文
获取原文并翻译 | 示例

摘要

The Chip Authentication Programme (CAP) has been introduced by banks in Europe to deal with the soaring losses due to online banking fraud. A handheld reader is used together with the customer's debit card to generate one-time codes for both login and transaction authentication. The CAP protocol is not public, and was rolled out without any public scrutiny. We reverse engineered the UK variant of card readers and smart cards and here provide the first public description of the protocol. We found numerous weaknesses that are due to design errors such as reusing authentication tokens, overloading data semantics, and failing to ensure freshness of responses. The overall strategic error was excessive optimisation. There are also policy implications. The move from signature to PIN for authorising point-of-sale transactions shifted liability from banks to customers; CAP introduces the same problem for online banking. It may also expose customers to physical harm.
机译:欧洲的银行已经引入了芯片认证程序(CAP),以应对由于在线银行欺诈而造成的飞速增长的损失。手持阅读器与客户的借记卡一起使用,可以生成用于登录和交易身份验证的一次性代码。 CAP协议不是公开的,并且在未进行任何公开审查的情况下推出。我们对英国的读卡器和智能卡变体进行了逆向工程,这里提供了该协议的第一个公开说明。我们发现了许多由于设计错误而引起的弱点,例如重用身份验证令牌,数据语义过载以及无法确保响应的新鲜度。总体战略错误是过度优化。还有政策含义。从用于授权销售点交易的签名到PIN的转变将负债从银行转移到了客户。 CAP对网上银行也引入了同样的问题。它还可能使客户遭受人身伤害。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号