Transit Payment System Security WP

ثبت نشده
چکیده

The Smart Card Alliance is a not-for-profit, multi-industry association working to stimulate the understanding, adoption, use and widespread application of smart card technology. Through specific projects such as education programs, market research, advocacy, industry relations and open forums, the Alliance keeps its members connected to industry leaders and innovative thought. The Alliance is the single industry voice for smart cards, leading industry discussion on the impact and value of smart cards in the U.S. and Latin America. For more information please visit Alliance has used best efforts to ensure, but cannot guarantee, that the information described in this report is accurate as of the publication date. The Smart Card Alliance disclaims all warranties as to the accuracy, completeness or adequacy of information in this report. Transit agencies worldwide have implemented automatic fare collection (AFC) systems that use contactless smart card technology for transit-issued fare media. These systems are popular since they deliver fast, easy access to riders and reduced operating costs and improved efficiencies to transit operators. Recently, questions about the security of these systems arose when researchers reverse engineered one contactless chip product – the MIFARE Classic product – that is used in many transit AFC systems. The Transportation Council of the Smart Card Alliance prepared this white paper to discuss this research and to outline the approaches that the transit industry uses throughout its payment systems to ensure the security of transactions and data. The MIFARE Classic product was introduced over 10 years ago as one of the original contactless integrated circuit (IC) products and used encryption and design strategies consistent with the time of development. Since then and since the completion of the ISO/IEC 14443 contactless smart card standard, multiple vendors introduced a variety of contactless IC products. Many of these products incorporate more modern and sophisticated designs and are used in global transit projects and other applications. These newer products have not been exposed to the recently announced breach. It is also important to remember that while the contactless smart card technology that is used by both transit and financial industries operates on the 13.56MHz frequency band, there are vast differences among the contactless applications and security approaches used. For example, the MIFARE Classic product is not being used for open bank card payments in the U.S. or in countries implementing EMV 1 ; these applications have additional security, functionality, and flexibility requirements. Transit agencies who …

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

User evaluation of three wheelchair securement systems in large accessible transit vehicles.

Ease of use, comfort, security, and independent use of three types of wheelchair securement systems were evaluated in a large accessible transit vehicle by 20 wheelchair and scooter users. The securement systems included a 4-point tie-down system, a prototype autodocking system, and a prototype rear-facing wheelchair passenger (RF-WP) system. Study participants took a 15-minute city ride and co...

متن کامل

The Presentation of an Ideal Safe SMS based model in mobile Electronic commerce using Encryption hybrid algorithms AES and ECC

Mobile commerce is whatever electronic transfer or transaction via a mobile modem through a mobile net in which the true value or advance payment is done for goods, services or information. A mobile payment system should be beneficial for all related persons. For a payment system to be a Successful system, End-user, seller, exporter and operators should see a additional value in it. End-user ...

متن کامل

An Interoperable Payment Protocol for the Public Transit Fare Payment System

The market for the public transit fare payment system using contactless smart cards is rapidly growing, however, the payment systems provided by different vendors are not interoperable. This paper presents an interoperable payment protocol for the public transit fare payment system using contactless smart cards. We also present implementation results of a PSAM (Purchase Secure Application Modul...

متن کامل

A NEW PROTOCOL MODEL FOR VERIFICATION OF PAYMENT ORDER INFORMATION INTEGRITY IN ONLINE E-PAYMENT SYSTEM USING ELLIPTIC CURVE DIFFIE-HELLMAN KEY AGREEMENT PROTOCOL

Two parties that conduct a business transaction through the internet do not see each other personally nor do they exchange any document neither any money hand-to-hand currency. Electronic payment is a way by which the two parties transfer the money through the internet. Therefore integrity of payment and order information of online purchase is an important concern. With online purchase the cust...

متن کامل

بررسی تأثیر روش پرداخت بر عملکرد پزشکان جراحی عمومی در بیمارستان‌های دولتی، خصوصی و تأمین اجتماعی در تهران

Background: There are many factors in the present system of health care that can lead to changes in the quality and quantity of services. Payment system is the most important factor. Empirical evidence shows that financial incentives are the most important factors affecting individual and organizational behavior in the health sector. The project aims to investigate the effects of payment method...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2008