Logo image
More is Less: Extra Features in Contactless Payments Break Security
Conference proceeding   Open access

More is Less: Extra Features in Contactless Payments Break Security

George Pavlides, Anna Clee, Ioana Boureanu and Tom Chothia
SEC '25: Proceedings of the 34th USENIX Conference on Security Symposium, pp.7977-7996
34th USENIX Security Symposium (Seattle, 13/08/2025–15/08/2025)
13/08/2025

Abstract

The EMV contactless payment system has many independent parties: payment providers, smartphone companies, banks and regulators. EMVCo publishes a 15 book specification that these companies use to operate together. However, many of these parties have independently added additional features, such as Square restricting offline readers to phone transactions only, Apple, Google and Samsung implementing transit modes and Visa and Mastercard complying with regional regulations on high value contactless payments. We investigate these features and find that these parties have been independently retrofitting and overloading the core EMV specification. Subtle interactions and mismatches between the different companies' additions lead to a range of vulnerabilities, making it possible to bypass restrictions to smartphone only payments, make unauthenticated high value transactions offline, and use a cloned card to make a £25000 transaction offline. To find fixes, we build formal models of the EMV protocol with the new features we investigated and test different possible solutions. We have engaged with EMV stakeholders and worked with the company Square to implement these fixes.
url
https://research.birmingham.ac.uk/en/publications/a9ab7abf-464b-45d4-9d31-08ed87bdbeb9View
Open access location Green open access via University of Birmingham repository Open
url
https://www.usenix.org/system/files/usenixsecurity25-pavlides.pdfView
Published (Version of record) Open

Metrics

29 Record Views

Details

Logo image

Usage Policy