SoK: Security of EMV Contactless Payment Systems

📅 2025-04-17
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This work addresses critical security vulnerabilities in the Visa/Mastercard open-loop EMV contactless payment systems. We systematically identify and empirically validate seven distinct attack vectors spanning the application selection, cardholder verification, and transaction authorization phases. Leveraging protocol reverse engineering, NFC side-channel analysis, compliance verification against ISO/IEC 14443 and EMV specifications, and a custom-built near-field experimental platform, we conduct the first cross-protocol security comparison of these two major international payment standards and establish a structured attack taxonomy. All attacks are confirmed feasible on commercially deployed terminals, revealing multiple previously undisclosed protocol flaws. Our findings provide empirical evidence to inform EMV standard evolution and terminal security hardening. We further propose a layered, implementable defense framework grounded in our experimental results.

Technology Category

Application Category

📝 Abstract
The widespread adoption of EMV (Europay, Mastercard, and Visa) contactless payment systems has greatly improved convenience for both users and merchants. However, this growth has also exposed significant security challenges. This SoK provides a comprehensive analysis of security vulnerabilities in EMV contactless payments, particularly within the open-loop systems used by Visa and Mastercard. We categorize attacks into seven attack vectors across three key areas: application selection, cardholder authentication, and transaction authorization. We replicate the attacks on Visa and Mastercard protocols using our experimental platform to determine their practical feasibility and offer insights into the current security landscape of contactless payments. Our study also includes a detailed evaluation of the underlying protocols, along with a comparative analysis of Visa and Mastercard, highlighting vulnerabilities and recommending countermeasures.
Problem

Research questions and friction points this paper is trying to address.

Analyze security vulnerabilities in EMV contactless payment systems
Categorize attacks into seven vectors across three key areas
Evaluate protocols and recommend countermeasures for vulnerabilities
Innovation

Methods, ideas, or system contributions that make the work stand out.

Analyzes EMV contactless payment security vulnerabilities
Replicates attacks using experimental platform
Evaluates protocols and recommends countermeasures
🔎 Similar Papers
No similar papers found.
M
Mahshid Mehr Nezhad
Secure Cyber Systems Research Group (SCSRG), WMG, University of Warwick, UK
F
Feng Hao
Department of Computer Science, University of Warwick, UK
Gregory Epiphaniou
Gregory Epiphaniou
Reader in Security Engineering, University of Warwick
Cyber threat source modelingCyber resilienceCyber securityPhysical Layer Security
Carsten Maple
Carsten Maple
Professor of Cyber Systems Engineering, University of Warwick
SecurityPrivacy and Trust
T
Timur Yunusov
Payment Village, UK