Abstract
The availability of NFC smartphones has facilitated the development of a large number of related applications. Some of these NFC applications necessitate communication with other systems, which may not necessarily be secure, through communication channels and mechanisms that may be open to vulnerabilities. Security is therefore paramount to the success of these NFC mobile services. While Peer-to-Peer (P2P) communication mode is common in mobile NFC applications, it is vulnerable to security-related issues that arise from the use of untrusted devices for storage and to process applications. We propose the concept of a Cloud of Secure Elements (CoSE) where the secure services are hosted by servers rather than by smartphone Secure Elements. We discuss the use of CoSE for mobile payments. We also illustrate how an NFC smartphone may be efficiently used as a bridge between an NFC reader and an Internet server of secure microcontroller that hosts EMV applications.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Preview
Unable to display preview. Download preview PDF.
Similar content being viewed by others
References
Jurgensen, T.M., et al.: Smart Cards: The Developer’s Toolkit. Prentice Hall PTR (2002) ISBN 0130937304
MasterCard® PayPassTM, M/Chip, Acquirer Implementation Requirements, v.1-A4 6/06
ISO/IEC 18092, Information technology - Telecommunications and information exchange between systems - Near Field Communication - Interface and Protocol (NFCIP-1) (April 2004)
Hancke, G.: A Practical Relay Attack on ISO 14443 Proximity Cards (January 2005)
Francis, L., Hancke, G., Mayes, K., Markantonakis, K.: Practical NFC peer-to-peer relay attack using mobile phones. In: Ors Yalcin, S.B. (ed.) RFIDSec 2010. LNCS, vol. 6370, pp. 35–49. Springer, Heidelberg (2010)
Roland, M.: Applying recent secure element relay attack scenarios to the real world: Google Wallet Relay Attack, technical report (August 2012)
Reid, J., et al.: Detecting Relay Attacks with Timing-Based Protocols. In: Proceedings of the 2nd ACM Symposium on Information, Computer and Communications Security (2007)
Sidén, J., Skerved, V., Gao, J., Forsström, S., Nilsson, H.-E., Kanter, T., Gulliksson, M.: Home Care with NFC Sensors and a Smart Phone. In: Proceedings of the 4th International Symposium on Applied Sciences in Biomedical and Communication Technologies (ISABEL), vol. 150, pp. 1–5 (2011)
Hancke, G.P., Opperman, C.: A Generic NFC-enabled Measurement System for Remote Monitoring and Control of Client-side Equipment. In: Proceedings of the Third IEEE International Workshop on Near Field Communication, pp. 44–49 (2011)
Morak, J., Kumpusch, H., Hayn, D., Modre-Osprian, R., Schreier, G.: Design and Evaluation of a Telemonitoring Concept Based on NFC-Enabled Mobile Phones and Sensor Devices. IEEE Transactions on Information Technology in Medicine 16(1), 17–23 (2012)
González, G.R., Organero, M.M., Kloos, C.D.: Early Infrastructure of an Internet of Things in Spaces for Learning. In: Proceedings of the Eighth IEEE International Conference on Advanced Learning Technologies (ICALT), pp. 381–383 (2008)
Widmann, R., Gruenberger, S., Stadlmann, B., Langer, J.: System Integration of NFC Ticketing into an Existing Public Transport Infrastructure. In: Proceedings of the 4th International Workshop on Near Field Communication, pp. 13–18 (2012)
Chaumette, S., Dubernet, D., Ouoba, J., Siira, E., Tuikka, T.: Architecture and Comparison of Two Different User-Centric NFC-Enabled Event Ticketing Approaches. In: Balandin, S., Koucheryavy, Y., Hu, H. (eds.) NEW2AN 2011 and ruSMART 2011. LNCS, vol. 6869, pp. 165–177. Springer, Heidelberg (2011)
Mainetti, L., Patrono, L., Vergallo, R.: IDA-Pay: An Innovative Micro-Payment System Based on NFC Technology for Android Mobile Devices. In: Proceedings of the 20th IEEE International Conference on Software, Telecommunications and Computer Networks (SoftCOM), pp. 1–6 (2012)
Monteiro, D.M., Rodrigues, J.J.P.C., Lloret, J., Sendra, S.: A Hybrid NFC–Bluetooth Secure Protocol for Credit Transfer among Mobile Phones. In: Security and Communication Networks (2013), doi:10.1002/sec.732
Urien, P., Piramuthu, S.: Framework and Authentication Protocols for Smartphone, NFC, and RFID in Retail Transactions. In: Proceedings of the 8th IEEE International Conference on Intelligent Sensors, Sensor Networks and Information Processing (ISSNIP), pp. 77–82 (2013)
Urien, P., Piramuthu, S.: LLCPS and SISO: A TLS-Based Framework with RFID for NFC P2P Retail Transaction Processing. In: Proceedings of IEEE International Conference on RFID, pp. 152–159 (2013)
Miller, C.: Don’t Stand So Close to Me: An Analysis of the NFC Attack Surface (July 25, 2012), http://www.blackhat.com/usa/bh-us-12-briefings.html#miller
Urien, P., Piramuthu, S.: Identity-Based Authentication to Address Relay Attacks in Temperature Sensor-enabled Smartcards. In: Proceedings of the European Conference on Smart Objects, Systems and Technologies (Smart SysTech), Erlangen/Nuremberg (2013)
Mulliner, C.: Vulnerability Analysis and Attacks on NFC-enabled Mobile Phones. In: Fourth International Conference on Availability, Reliability and Security (ARES), pp. 695–700 (2009)
Ries, U.: “Phishing via NFC,” The H Security (March 2, 2012), http://www.webcitation.org/6BzrM8Qmp
Borgaonkar, R.: USSD/Android Dailer vulnerability (June 2012), http://www.webcitation.org/6DW71H3uK
Lee, E.: NFC Hacking: The Easy Way, DEFCON 20 (July 2012)
ISO 7816, Cards Identification - Integrated Circuit Cards with Contacts
Urien, P.: LLCPS: A New Security Framework Based on TLS For NFC P2P Applications in the Internet of Things, IEEE CCNC 2013 (January 2013)
Urien, P., Piramuthu, S.: Towards a Secure Cloud of Secure Elements Concepts and Experiments with NFC Mobiles. In Proceeding of the CTS 2013 Conference (May 2013)
AWS CloudHSM Getting Started Guide, Kindle Edition, Amazon WEB Services (2013)
SECFUNET, a research project funded by the European Commission’s Framework Programme 7 and CNPq, the Brazilian National Council for Technological and Scientific Development, http://www.secfunet.eu
IETF Draft, Remote APDU Call Secure (RACS), draft-urien-core-racs-00 (August. 2013)
Author information
Authors and Affiliations
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2014 ICST Institute for Computer Science, Social Informatics and Telecommunications Engineering
About this paper
Cite this paper
Urien, P., Piramuthu, S. (2014). Securing NFC Mobile Services with Cloud of Secure Elements (CoSE). In: Memmi, G., Blanke, U. (eds) Mobile Computing, Applications, and Services. MobiCASE 2013. Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering, vol 130. Springer, Cham. https://doi.org/10.1007/978-3-319-05452-0_30
Download citation
DOI: https://doi.org/10.1007/978-3-319-05452-0_30
Publisher Name: Springer, Cham
Print ISBN: 978-3-319-05451-3
Online ISBN: 978-3-319-05452-0
eBook Packages: Computer ScienceComputer Science (R0)