Toggle Main Menu Toggle Search

Open Access padlockePrints

Tap-Tap and Pay (TTP): Preventing the Mafia Attack in NFC Payment

Lookup NU author(s): Maryam Mehrnezhad, Professor Feng Hao, Dr Siamak Fayyaz Shahandashti

Downloads

Full text for this publication is not currently held within this repository. Alternative links are provided below where available.


Abstract

Mobile NFC payment is an emerging industry, estimated to reach $670 billion by 2015. The Mafia attack presents a realistic threat to payment systems including mobile NFC payment. In this attack, a user consciously initiates an NFC payment against a legitimate-looking NFC reader (controlled by the Mafia), not knowing that the reader actually relays the data to a remote legitimate NFC reader to pay for something more expensive. In this paper, we present "Tap-Tap and Pay" (TTP), to effectively prevent the Mafia attack in mobile NFC payment. In TTP, a user initiates an NFC payment by physically tapping her mobile phone against the reader twice in succession. The physical tapping causes transient vibrations at both devices, which can be measured by the embedded accelerometers. Our experiments indicate that the two measurements are closely correlated if they are from the same tapping, and are different if obtained from different tapping events. By comparing the similarity between the two measurements, we can effectively tell apart the Mafia fraud from a legitimate NFC transaction. To evaluate the practical feasibility of this solution, we present a prototype of the TTP system based on a pair of NFC-enabled mobile phones and also conduct a user study. The results suggest that our solution is reliable, fast, easy-to-use and has good potential for practical deployment.


Publication metadata

Author(s): Mehrnezhad M, Hao F, Shahandashti SF

Publication type: Conference Proceedings (inc. Abstract)

Publication status: Published

Conference Name: Security Standardisation Reseach (SSR 2015)

Year of Conference: 2015

Pages: 21-39

Print publication date: 01/01/2015

Online publication date: 08/12/2015

Acceptance date: 01/01/1900

Publisher: Springer International Publishing

URL: http://dx.doi.org/10.1007/978-3-319-27152-1_2

DOI: 10.1007/978-3-319-27152-1_2

Library holdings: Search Newcastle University Library for this item

Series Title: Lecture Notes in Computer Science

ISBN: 9783319271514


Share