Matching in Proximity Authentication and Mobile Payment EcoSystem: What Are We Missing?

Yunhui Zhuang*, Alvin Chung Man Leung, James Hughes

*Corresponding author for this work

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 12 - Chapter in an edited book (Author)peer-review

2 Citations (Scopus)

Abstract

During the past decade, cybersecurity threats have drawn everyone’s attention and it’s becoming a national priority in many leading countries. With the development of sophisticated mobile technology, mobile (contactless) payment insecurity, which may cause huge financial losses, is now becoming a serious threat to our daily life. During the holiday season in 2013, China’s most welcome mobile payment system provider - Alipay - lost over 20 GB worth of customer data in a security breach, which affected at least 15 million customers. Even though the company has promised to evaluate the security of the system and to take necessary measures to protect customer’s data, are we still safe with the payment? In this paper, we investigate several security vulnerabilities for Alipay wallet, which may cause individual’s personal data and financial losses. This is due to not only less regulation by authorities but also the failure of enabling secure proximity authentication during mobile payment. By going through these surprising vulnerabilities, we come up with some ideas on how to combat them and show how to enhance the mobile payment security by enabling proximity authentication before monetary transactions. © Springer International Publishing AG 2017
Original languageEnglish
Title of host publicationRadio Frequency Identification and IoT Security
Subtitle of host publication12th International Workshop, RFIDSec 2016, Hong Kong, China, November 30 -- December 2, 2016, Revised Selected Papers
EditorsGerhard P. Hancke, Konstantinos Markantonakis
Place of PublicationCham
PublisherSpringer 
Pages163-172
ISBN (Electronic)978-3-319-62024-4
ISBN (Print)9783319620237
DOIs
Publication statusPublished - 2017
Event12th International Workshop on Radio Frequency Identification and IoT Security (RFIDSec 2016) - Hong Kong, China
Duration: 30 Nov 20162 Dec 2016
https://rfidsec2016.org/

Publication series

NameLecture Notes in Computer Science
Volume10155
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference12th International Workshop on Radio Frequency Identification and IoT Security (RFIDSec 2016)
Abbreviated titleRFIDSec 2016
PlaceChina
CityHong Kong
Period30/11/162/12/16
Internet address

Research Keywords

  • Alipay wallet
  • Mobile payment
  • QR code
  • Security

Fingerprint

Dive into the research topics of 'Matching in Proximity Authentication and Mobile Payment EcoSystem: What Are We Missing?'. Together they form a unique fingerprint.

Cite this