Title :
Two-factor authentication for android host card emulated contactless cards
Author :
Munch-Ellingsen, Arne ; Karlsen, Richard ; Andersen, Anders ; Akselsen, Sigmund
Author_Institution :
Telenor Res., Tromso, Norway
Abstract :
With the introduction of Host Card Emulation (HCE) in Android 4.4 KitKat the Near Field Communication (NFC) card emulation mode took a twist. On one side, HCE allows for easier development and a shorter deployment path for contactless card services on the mobile phone (e.g. payment, ticketing, loyalty cards etc.). On the other side, it introduces new security issues since it does not intrinsically involve a secure element on the mobile phone. As an example, the Cipurse open ticketing standard for public transportation, published by OSPT, implies usage of a secure element for the authentication mechanism and key storage. How can Cipurse benefit from the advantages of HCE and still provide secure authentication and encryption of transferred data? We have designed a two-factor authentication mechanism that involves usage of the Universal Integrated Circuit Card (also known as the SIM card) as the secure second-factor that allows for the implementation of the Cipurse specification as a secure HCE application. The benefit is faster execution of the Cipurse emulated card but still with feasible security for many application areas.
Keywords :
Android (operating system); cryptography; near-field communication; smart phones; trusted computing; Android 4.4 KitKat; Android host card emulated contactless cards; Cipurse open ticketing standard; Cipurse specification; HCE application; NFC card emulation mode; OSPT; SIM card; Universal Integrated Circuit Card; authentication mechanism; data encryption; host card emulation; mobile phone; near field communication card emulation mode; public transportation; security issues; two-factor authentication mechanism; Androids; Authentication; Emulation; Humanoid robots; Mobile communication; Smart phones; Cipurse; Host Card Emulation; Near Field Communication; Trusted Service Manager;
Conference_Titel :
Mobile and Secure Services (MOBISECSERV), 2015 First Conference on
Conference_Location :
Gainesville, FL
DOI :
10.1109/MOBISECSERV.2015.7072874