Payment security, read the mobile payment fingerprint and QR code security issues


With the mass adoption of smartphones, mobile payment has also risen and is on the rise. According to statistics, as of the end of last year, the number of users using mobile payment in China has grown rapidly, reaching 469 million people, with an annual growth rate of 31.2%. It can be seen that mobile payment is favored by consumers and has gradually formed a new consumption trend.

The recently released 2017 China Mobile Security Risk Report shows that as mobile phones become more and more an integral part of the daily life of the masses, mobile payments are also growing rapidly, and they are gaining momentum. In 2016, China Mobile's total payment amounted to approximately 209 trillion yuan, exceeding the US full-year GDP in 2016. However, mobile payment, which is so popular and has been inseparable from the public, food and clothing, has hidden dangers that cannot be ignored. Yao Wei, assistant director of 360 Group and head of mobile guards, pointed out that the security of mobile payment is still worrying. 93% of phishing websites and 34.8% of malicious programs threaten personal property. If you accidentally, you may be ruined by a text message or a link. , mobile phone or into a property "black hole."

WeChat payment, mobile Alipay, APPLE PAY .... Where is the security issue of mobile payment?

1. Fingerprint security issues With the widespread use of fingerprint recognition technology on mobile phones, it has made its mark in the forefront and gradually matured. In fact, due to its novel payment model and convenient operation process, fingerprint payment has attracted a lot of attention and has attracted a large number of users. The entire payment process can be completed with one finger, without having to remember the password, making shopping quicker and faster.

At the recent Taipei Computer Show, Synaptics conducted such a related demonstration. A seemingly ordinary fingerprint recognition notebook, after the user uses fingerprint recognition, the criminals can capture the original data of the fingerprint sensor and wirelessly transmit the data to another machine, thereby copying the fingerprint of the owner, and then The imitation of the prosthetic fingerprint is used to complete the cracking of the same type of fingerprint device on the host computer and mobile phone, and the whole process is less than 20 minutes.

What is going on behind this? In fact, a fingerprint identification scheme can be called security. It needs to provide protection in many aspects such as fingerprint acquisition, transmission, storage, etc. The negligence of any link will directly affect the security of the system. Our common fingerprint recognition mainly focuses on the security of storage. For example, the mobile phone will call the independent TrustZone to ensure security. Individual devices will call a separate encryption chip to store fingerprint data, which brings a security impression.

But the fact is that this environment is after all the isolation of the software layer, the current solution is to use professional security chips to maintain key fingerprint data for SE. SE is an abbreviation of Secure Element, a security component provided in chip form. Currently, the standardization organizations defined for the security component standards mainly include EMV and Global platform. In order to prevent external malicious parsing attacks and protect data security, a logic circuit with encryption/decryption is added to the chip. Among them, SE plays the role of cooperation with TEE to strengthen system security. If the system manufacturer uses SE, the professionalism of the security chip issuer can be used to ensure the protection of the system hardware and software under illegal attacks.

2. Two-dimensional code security problem The QR code industry is creating one miracle after another in China. The most typical one is that under the promotion of two-dimensional code technology, the transaction amount of mobile payment in China has reached 50 times of the US market! Let the Chinese market become a veritable global king in the mobile Internet era.

However, the two-dimensional code is technically more dangerous than the fingerprint. The mobile phone virus and malicious programs that are transmitted by means of the two-dimensional code are also increasing. Since the two-dimensional code technology is relatively mature, ordinary users can pass the two-dimensional online. Code conversion software, arbitrarily synthesizing two-dimensional code, and can not judge its security from the appearance, which makes it more convenient for hackers to perform various illegal operations on the QR code. Once the user scans the two-dimensional code embedded in the virus link, Personal information, bank account numbers, passwords, etc. may be completely exposed to hackers, and the consequences can be imagined.

When the QR code scan logic is exposed, the scan code hijacking becomes very simple. The hacker can insert malicious code into the client that scans the payment, and tamper with the transaction data, so that the funds that should flow to the merchant flow to the hacker. The scan code attack is shown in the following figure:

At present, China UnionPay and mobile phone manufacturers have begun to pay attention to security issues in mobile payment, especially in the hardware of the chip to standardize security indicators, such as loading a professional security chip solution in the mobile phone, and need to pass the national secret certification. Although it will increase costs, as users' demands for security increase, it is believed that devices with security components will become more and more popular.

Car Perfume

Car perfume is kind of car air freshener .pouring with high quality essential oil perfume. good finishing glass bottle.put it in the car to refreshing the atmosphere or make charming ,have different design .hanging or put front desk of car,or clip on vent.The clip is very resistant and easy to use, by just attaching it to your car vent. It will stick just perfectly, without falling during bumps.this car perfume also can be used for hanging in toilet or room closet,like Room Diffuser or Fragrance Diffuser.

.,.car perfume air freshener

Car Perfume,Air Freshener

ZHEJIANG SHUN AN INDUSTRY & TRADE CO., LTD. , http://www.lonimaxdiffuser.com

Posted on