Security Analysis of Unified Payments Interface and Payment Apps in India

Security Analysis of Unified Payments Interface and Payment Apps in India
复制标题

DOI:
--
复制
发表时间:
2020
期刊:
影响因子:
3.9
通讯作者:
Renuka Kumar;S. Kishore;Hao Lu;A. Prakash
Renuka Kumar;S. Kishore;Hao Lu;A. Prakash
中科院分区:
材料科学3区
文献类型:
--
作者:
Renuka Kumar;S. Kishore;Hao Lu;A. Prakash

文献摘要

被引文献

相似文献

自2016年以来,在印度政府的强烈推动下,基于智能手机的付款应用程序已成为主流,2018年通过这些应用程序通过这些应用程序进行了超过500亿美元的交易。其中许多应用程序使用印度政府引入的共同基础设施付款接口(UPI),但是对支持转移的这一关键基础架构没有安全分析。七个流行的UPI应用程序。即使受害者从未使用UPI应用程序,也可以将受害者的银行帐户连接起来。层协议,包括所有UPI应用程序都在印度进行严格的安全性审查,并旨在抵抗分析。
Since 2016, with a strong push from the Government of India, smartphone-based payment apps have become mainstream, with over $50 billion transacted through these apps in 2018. Many of these apps use a common infrastructure introduced by the Indian government, called the Unified Payments Interface (UPI), but there has been no security analysis of this critical piece of infrastructure that supports money transfers. This paper uses a principled methodology to do a detailed security analysis of the UPI protocol by reverse-engineering the design of this protocol through seven popular UPI apps. We discover previously-unreported multi-factor authentication design-level flaws in the UPI 1.0 specification that can lead to significant attacks when combined with an installed attacker-controlled application. In an extreme version of the attack, the flaws could allow a victim’s bank account to be linked and emptied, even if a victim had never used a UPI app. The potential attacks were scalable and could be done remotely. We discuss our methodology and detail how we overcame challenges in reverse-engineering this unpublished application layer protocol, including that all UPI apps undergo a rigorous security review in India and are designed to resist analysis. The work resulted in several CVEs, and a key attack vector that we reported was later addressed in UPI 2.0.