错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

PayRide: Secure Transport e-Ticketing with Untrusted Smartphone Location

  • Marazzi Michele,
  • Patrick Jattke,
  • Jason Zibung,
  • Kaveh Razavi

摘要

The smartphone location is the basis for a plethora of popular applications, such as traffic navigation, games, and geotagging. Since the user can manipulate the reported location, it is possible to compromise these applications with fake locations. These attacks generally have a limited impact, but this is changing with the increasing level of trust in the smartphone location. As a prominent example, recent transport e-ticketing applications perform financial transactions based on the assumption that the smartphone location represents that of the user. Unfortunately, this assumption leads to location-based attacks with direct financial implications. We present FreeRide, a real-world attack that allows a malicious user to ride public transports for free. Existing mitigations against FreeRide are either ineffective or impractical since they attempt to enforce the integrity of the smartphone location. Instead of enforcing location integrity, our proposed mitigation, PayRide, establishes the user’s location using the position of the public transport. We have formally verified the PayRide protocol and evaluated its boundary conditions based on a range of possible accuracies reported by the smartphone and public transport.