Beware of Your Screen

Zhe Zhou,Di Tang,Wenhao Wang,Xiaofeng Wang,Zhou Li,Kehuan Zhang
DOI: https://doi.org/10.1145/3274694.3274721
2018-01-01
Abstract:QR-code mobile payment becomes increasingly popular, being offered by major banks (e.g., ICBC) and payment service providers (e.g., PayPal). Unlike mobile payment solutions provided by hardware vendors (e.g., Apple Pay and Samsung Pay), QR code payment schemes do not rely on any hardware support and can therefore be easily deployed. However, the security guarantee of the new scheme is less clear: in the absence of hardware protection, users' digital wallet can be vulnerable to an OS-level adversary, who could steal her secret for generating payment tokens.
What problem does this paper attempt to address?