Skip to main content
Article
Towards more secure EMV purchase transactions: A new security protocol formally analyzed by the Scyther tool
Annales des Telecommunications/Annals of Telecommunications
  • Nour El Madhoun, ISEP
  • Emmanuel Bertin, Orange Labs
  • Mohamad Badra, Zayed University
  • Guy Pujolle, Sorbonne Universite
ORCID Identifiers

0000-0001-7742-7748

Document Type
Article
Publication Date
1-1-2020
Abstract

© 2020, Institut Mines-Télécom and Springer Nature Switzerland AG. EMV is the protocol implemented to secure the communication, between a client’s payment device and a merchant’s payment device, during a contact or an NFC purchase transaction. It represents a set of security messages and rules, exchanged between the different transaction actors, guaranteeing several important security properties, such as authentication, non-repudiation and integrity. Indeed, researchers, in various studies, have analyzed the operation of this protocol in order to verify its safety: unfortunately, they have identified two security vulnerabilities that lead to multiple attacks and dangerous risks threatening both clients and merchants. In this paper, we are firstly interested in presenting a general overview of the EMV protocol and secondly, in proposing a new security solution that enhances the EMV protocol by solving the two dangerous EMV vulnerabilities. We verify the accuracy of our solution by using the Scyther security verification tool.

Publisher
Springer
Disciplines
Keywords
  • Authentication,
  • Bank,
  • Card,
  • Confidentiality,
  • EMV,
  • NFC,
  • Security,
  • Vulnerabilities
Scopus ID
85088092915
Indexed in Scopus
Yes
Open Access
No
https://doi.org/10.1007/s12243-020-00784-1
Citation Information
Nour El Madhoun, Emmanuel Bertin, Mohamad Badra and Guy Pujolle. "Towards more secure EMV purchase transactions: A new security protocol formally analyzed by the Scyther tool" Annales des Telecommunications/Annals of Telecommunications (2020) - 20 ISSN: <a href="https://v2.sherpa.ac.uk/id/publication/issn/0003-4347" target="_blank">0003-4347</a>
Available at: http://works.bepress.com/mohamad-badra/21/