Netinfo Security ›› 2020, Vol. 20 ›› Issue (2): 49-56.doi: 10.3969/j.issn.1671-1122.2020.02.007

• 技术研究 • Previous Articles     Next Articles

Risk Assessment of Mobile Payment System Based on STRIDE and Fuzzy Comprehensive Evaluation

LIU Yonglei1,2(), JIN Zhigang1, HAO KUN2, ZHANG Weilong3   

  1. 1. School of Electrical and Information Engineering, Tianjin University, Tianjin 300072, China
    2. School of Computer and Information Engineering, Tianjin Chengjian University, Tianjin 300384, China
    3. Quality Management Center, Hebei Jiaotong Vocational and Technical College, Shijiazhuang 050035, China
  • Received:2019-08-15 Online:2020-02-10 Published:2020-05-11

Abstract:

With the development of mobile communication technology and the popularity of smart phones, mobile payment is becoming more and more popular. However, the security weaknesses of wireless networks, system vulnerabilities in mobile devices, and account hijacking have all contributed to the security of mobile payments. This paper starts with the mobile payment transaction process, analyzes the security threat of mobile payment system, and proposes a risk assessment method, so that both parties can conduct security assessment on the transaction process to make security decisions. The method uses the STRIDE threat model to build an indicator system and uses a fuzzy comprehensive evaluation method to assess the risk of the transaction. A threat mitigation model based on trusted network connection (TNC) is established, and the security of mobile payment system is enhanced according to the evaluation result. Quantitative indicators are used in the assessment and a transaction-level fine-grained risk assessment is achieved. At the end of this paper, the risk assessment method is validated and analyzed by using two typical application scenarios.

Key words: mobile payment, risk assessment, fuzzy comprehensive evaluation

CLC Number: