www射-国产免费一级-欧美福利-亚洲成人福利-成人一区在线观看-亚州成人

USEUROPEAFRICAASIA 中文雙語Fran?ais
China
Home / China / Society

CUHK researchers discover major loophole in mobile payment systems

Xinhua | Updated: 2017-09-28 17:10
HONG KONG - A major loophole in mobile payment systems was discovered by researchers from the Chinese University of Hong Kong (CUHK), which made the finding public on Thursday.

The discovery was made by the System Security Lab led by Professor Kehuan Zhang from the Department of Computer Science and Engineering at CUHK, which has analyzed various major mobile payment systems for their security vulnerabilities.

In mobile payment transactions, the key to communications between the mobile payer and payee is a payment token that is issued by the payment service provider to verify the payment.

Some of the most widely adopted forms of transmitting these tokens include Near-Field Communication (NFC), Quick Response Code (QR code) scans and Magnetic Secure Transmission (MST).

According to Zhang, whose team has spent two years in conducting an in-depth study into these payment systems, apart from NFC, the remaining formats support one-way communications only.

In other words, if the transaction fails, the payee's device is unable to notify the payer and cancel or reclaim the token already issued, a loophole that an active adversary can exploit.

In regard to QR Code scanning, a popular format of token verification, the study has revealed that a malicious device is able to sniff the token from the payee's screen from afar and spend it on a different transaction.

As for MST function uniquely used by Samsung Pay, payers are required to place their handsets within a 7.5 cm distance of the payees' POS (Point of sale) for identification.

But after a series of tests, the team discovered that the magnetic signals can be picked up from 2 meters away. A rogue in a supermarket queue can seize the opportunity to attack and steal the token.

The team has notified relevant third party payment platforms and Zhang reminded mobile payment users to stay alert and avoid downloading mobile apps from unknown sources.

Editor's picks
Copyright 1995 - . All rights reserved. The content (including but not limited to text, photo, multimedia information, etc) published in this site belongs to China Daily Information Co (CDIC). Without written authorization from CDIC, such content shall not be republished or used in any form. Note: Browsers with 1024*768 or higher resolution are suggested for this site.
License for publishing multimedia online 0108263

Registration Number: 130349
FOLLOW US
 
主站蜘蛛池模板: 欧美日韩精品一区二区免费看 | 亚洲久久网站 | 456亚洲老头视频 | 中国精品视频一区二区三区 | 国产a久久精品一区二区三区 | 日本美女黄色一级片 | 欧美成人性色xxxx视频 | 久久久久久久久久久9精品视频 | a一级毛片免费高清在线 | 久久免费视频在线 | 一级毛片aaa片免费观看 | 日韩毛片欧美一级a | 国内精品久久久久久网站 | 美女很黄很黄是免费的·无遮挡网站 | 高清偷自拍第1页 | 亚洲精品区一区二区三区四 | 日本久久草 | 亚洲一区二区三区首页 | 久久国内精品自在自线观看 | 久久中文字幕久久久久91 | 成人亚洲欧美综合 | 亚洲孕交 | 国产主播福利精品一区二区 | 国产性夜夜春夜夜爽30 | 国产精品国产高清国产专区 | 亚洲一区二区精品视频 | 污全彩肉肉无遮挡彩色 | 免费色网址 | 国内自拍亚洲 | 国产精品久久精品视 | 天堂精品高清1区2区3区 | 精品国产高清a毛片无毒不卡 | 国产在线精品一区二区三区 | 欧美α一级毛片 | 亚洲香蕉久久一区二区三区四区 | 久久久久久久久久久久久久久久久 | 国产dvd毛片在线视频 | 欧美精品高清 | 日本三本道 | 韩国理伦一级毛片 | 国产一区日韩二区欧美三 |