2008Security and Communication NetworksRequires access

Protecting TLS‐SA implementations for the challenge‐response feature of EMV‐CAP against challenge collision attacks

Rolf Oppliger, Ralf Hauser

Open publisher page 4 citations

Abstract

Abstract Secure Sockets Layer (SSL)/Transport Layer Security (TLS) session‐aware user authentication (TLS‐SA) can be used to protect SSL/TLS‐based e‐commerce applications against man‐in‐the‐middle (MITM) attacks. The main idea is to make the user authentication depend not only on the user's credentials, but also on state information related to the SSL/TLS session in which the credentials are transferred to the server. This, in turn, allows the server to detect inconsistencies caused by an MITM. There are many possibilities to implement TLS‐SA and to make a user authentication scheme be SSL/TLS session‐aware. In this paper, we take the challenge‐response (C/R) feature of the Europay International, MasterCard, and Visa (EMV) Chip Authentication Program (CAP) as an example, and we argue that a TLS‐SA implementation for this feature is appropriate but susceptible to challenge collision attacks. We then pick challenge collision attacks out as a central theme, and elaborate on a possible protection mechanism. Assuming that the adversary has no access to the browser's graphical user interface (GUI) and cannot retrieve the EMV‐CAP challenge accordingly, the level of protection against challenge collision attacks can be improved considerably by non‐deterministically derivating the challenge from information related to the SSL/TLS session and using encryption to turn a challenge into a response. If the adversary has read access to the browser's GUI, then this approach is counterproductive, and if the adversary even has write access, then the use of EMV‐CAP is insecure and problematic in the first place. Copyright © 2008 John Wiley & Sons, Ltd.

About this research paper

What this paper is about

Abstract Secure Sockets Layer (SSL)/Transport Layer Security (TLS) session‐aware user authentication (TLS‐SA) can be used to protect SSL/TLS‐based e‐commerce applications against man‐in‐the‐middle (MITM) attacks. The main idea is to make the user authentication depend not only on the user's credentials, but also on state information related to the SSL/TLS session in which the credentials are transferred to the server. This, in turn, allows the server to detect inconsistencies caused by an MITM. There are many possibilities to implement TLS‐SA and to make a user authentication scheme be SSL/TLS session‐aware. In this paper, we take the challenge‐response (C/R) feature of the Europay International, MasterCard, and Visa (EMV) Chip Authentication Program (CAP) as an example, and we argue that a TLS‐SA implementation for this feature is appropriate but susceptible to challenge collision attacks. We then pick challenge collision attacks out as a central theme, and elaborate on a possible protection mechanism. Assuming that the adversary has no access to the browser's graphical user interface (GUI) and cannot retrieve the EMV‐CAP challenge accordingly, the level of protection against challenge collision attacks can be improved considerably by non‐deterministically derivating the challenge from information related to the SSL/TLS session and using encryption to turn a challenge into a response. If the adversary has read access to the browser's GUI, then this approach is counterproductive, and if the adversary even has write access, then the use of EMV‐CAP is insecure and problematic in the first place. Copyright © 2008 John Wiley & Sons, Ltd.

Why it matters

OpenAlex reports 4 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Abstract Secure Sockets Layer (SSL)/Transport Layer Security (TLS) session‐aware user authentication (TLS‐SA) can be used to protect SSL/TLS‐based e‐commerce applications against man‐in‐the‐middle (MITM) attacks. The main idea is to make the user authentication depend not only on the user's credentials, but also on state information related to the SSL/TLS session in which the credentials are transferred to the server. This, in turn, allows the server to detect inconsistencies caused by an MITM. There are many possibilities to implement TLS‐SA and to make a user authentication scheme be SSL/TLS session‐aware. In this paper, we take the challenge‐response (C/R) feature of the Europay International, MasterCard, and Visa (EMV) Chip Authentication Program (CAP) as an example, and we argue that a TLS‐SA implementation for this feature is appropriate but susceptible to challenge collision attacks. We then pick challenge collision attacks out as a central theme, and elaborate on a possible protection mechanism. Assuming that the adversary has no access to the browser's graphical user interface (GUI) and cannot retrieve the EMV‐CAP challenge accordingly, the level of protection against challenge collision attacks can be improved considerably by non‐deterministically derivating the challenge from information related to the SSL/TLS session and using encryption to turn a challenge into a response. If the adversary has read access to the browser's GUI, then this approach is counterproductive, and if the adversary even has write access, then the use of EMV‐CAP is insecure and problematic in the first place. Copyright © 2008 John Wiley & Sons, Ltd.

Key concepts: Computer science, Man-in-the-middle attack, Adversary, Transport Layer Security, Computer security, Session (web analytics), Authentication (law), Computer network

Related papers

Back to paper searchBrowse research topicsOriginal source
Protecting TLS‐SA implementations for the challenge‐response feature of EMV‐CAP against challenge collision attacks — Research Paper | ScholarLens