Large-scale invisible attack on AFC systems with NFC-equipped smartphones

Large-scale invisible attack on AFC systems with NFC-equipped smartphones
复制标题

DOI:
10.1109/infocom.2017.8057219
复制
发表时间:
2017-05
期刊:
IEEE INFOCOM 2017 - IEEE Conference on Computer Communications
影响因子:
--
通讯作者:
Fan Dang;Pengfei Zhou;Zhenhua Li;Ennan Zhai;Aziz Mohaisen;Q. Wen;Mo Li
Fan Dang;Pengfei Zhou;Zhenhua Li;Ennan Zhai;Aziz Mohaisen;Q. Wen;Mo Li
中科院分区:
其他
文献类型:
--
作者:
Fan Dang;Pengfei Zhou;Zhenhua Li;Ennan Zhai;Aziz Mohaisen;Q. Wen;Mo Li

文献摘要

被引文献

相似文献

自动售检票(AFC)系统已经在全球部署了几十年,特别是在公共交通领域。虽然AFC系统的交易信息大多以明文形式传输,这显然是不安全的,但系统运营商不需要过多关注这个问题,因为AFC网络与公共网络(例如,互联网)。然而,近年来,配备近场通信(NFC)的智能手机的出现通过基于主机的卡仿真(HCE)弥合了AFC网络和互联网之间的差距。基于这一事实,我们设计并实践了一种新的模式,对现代基于距离的AFC系统进行攻击,使用户能够支付比实际需要少得多的费用。我们构造的攻击具有两个重要特性:1)它对AFC系统运营商是不可见的,因为攻击永远不会在运营商的后端数据库中引起任何不一致;以及2)它可以扩展到大量用户(例如,10,000)通过维持中等规模的AFC卡池(例如,共150张卡片)。基于这种构造的攻击,我们开发了一个名为LessPay的HCE应用程序。我们在LessPay上的真实实验不仅证明了我们攻击的可行性(成功率为97.6%),而且在带宽和计算方面的开销也很低。
Automated Fare Collection (AFC) systems have been globally deployed for decades, particularly in public transportation. Although the transaction messages of AFC systems are mostly transferred in plaintext, which is obviously insecure, system operators do not need to pay much attention to this issue, since the AFC network is well isolated from public network (e.g., the Internet). Nevertheless, in recent years, the advent of Near Field Communication (NFC)-equipped smartphones has bridged the gap between the AFC network and the Internet through Host-based Card Emulation (HCE). Motivated by this fact, we design and practice a novel paradigm of attack on modern distance-based pricing AFC systems, enabling users to pay much less than actually required. Our constructed attack has two important properties: 1) it is invisible to AFC system operators because the attack never causes any inconsistency in the backend database of the operators; and 2) it can be scalable to large number of users (e.g., 10,000) by maintaining a moderate-sized AFC card pool (e.g., containing 150 cards). Based upon this constructed attack, we developed an HCE app, named LessPay. Our real-world experiments on LessPay demonstrate not only the feasibility of our attack (with 97.6% success rate), but also its low-overhead in terms of bandwidth and computation.