For Small Merchants: A Secure Smartphone-Based Architecture to Process and Accept NFC Payments
Résumé
EMV is the international protocol implemented to secure the communication between a client's payment device and a PoS during a contact or an NFC purchase transaction. It guarantees several important security properties such as authentication, authorization and integrity. However, researchers, in various studies, have analyzed this protocol and have shown that it is vulnerable to several kinds of attacks. In this paper, we propose an innovative security protocol that solves the EMV vulnerabilities in the context of a new NFC payment architecture. The latter is designed in this work and is especially destined for small merchants, allowing to replace the use of a mobile PoS by an NFC smartphone: we suggest, for a small merchant, to take advantage of his NFC smartphone for use as an NFC reader, and then, directly as a PoS to accept NFC purchases from client payment devices. We check the accuracy of our proposal using the Scyther security tool.