Free Rides in Denmark: Lessons from Improperly Generated Mobile Transport Tickets

被引:4
|
作者
Giustolisi, Rosario [1 ]
机构
[1] IT Univ Copenhagen, Copenhagen, Denmark
来源
关键词
D O I
10.1007/978-3-319-70290-2_10
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The term security ceremony describes a technical system extended with its human users. In this paper, we examine the inspection ceremony for the mobile transport ticket in Denmark. We find several security weaknesses that are ascribable to both human and computer components of the ceremony. The main vulnerabilities are due to the design choices of how the visual inspection ceremony is organised and the lack of information that is stored into the 2D barcode. These vulnerabilities allow a ticket holder to travel up to 8 zones with a 2-zone subscription and enable several people to travel with the same subscription. The attack is significant as it can be automated, and rather modest skills are necessary to break the inspection ceremony. We state four principles that aim at strengthening the security of inspection ceremonies and propose an alternative ceremony whose design is driven by the stated principles.
引用
下载
收藏
页码:159 / 174
页数:16
相关论文
共 8 条
  • [2] The mobile-stationary divide in ubiquitous computing environments. Lessons from the transport industry
    Andersson, M
    Lindgren, R
    INFORMATION SYSTEMS MANAGEMENT, 2005, 22 (04) : 65 - 79
  • [3] Impact and assessment of "Free" Public Transport measures: lessons from the case study of Brussels
    Macharis, Cathy
    De Witte, Astrid
    Steenberghen, Therese
    Van de Walle, Stefaan
    Lannoy, Pierre
    Polain, Celine
    EUROPEAN TRANSPORT-TRASPORTI EUROPEI, 2006, (32): : 26 - 48
  • [4] COMPENSATION DENSITIES IN NORMAL-TYPE HG1-XCDXTE FROM TRANSPORT-PROPERTIES OF OPTICALLY GENERATED FREE-CARRIERS
    BARTOLI, FJ
    HOFFMAN, CA
    MEYER, JR
    JOURNAL OF VACUUM SCIENCE & TECHNOLOGY A-VACUUM SURFACES AND FILMS, 1983, 1 (03): : 1669 - 1671
  • [5] Workshop 3B: Governance, ownership and competition issues in deregulated (free market) public transport: Lessons that can be learnt from developed and developing economies
    van de Velde, Didier
    Preston, John
    RESEARCH IN TRANSPORTATION ECONOMICS, 2013, 39 (01) : 202 - 207
  • [6] Analysis of 23 364 patient-generated, physician-reviewed malpractice claims from a non-tort, blame-free, national patient insurance system:: lessons learned from Sweden
    Pukk-Harenstam, K.
    Ask, J.
    Brommels, M.
    Thor, J.
    Penaloza, R. V.
    Gaffney, F. A.
    QUALITY & SAFETY IN HEALTH CARE, 2008, 17 (04): : 259 - 263
  • [7] Analysis of 23 364 patient-generated, physician-reviewed malpractice claims from a non-tort, blame-free, national patient insurance system: lessons learned from Sweden (Reprinted from Quality & Safety in Health Care, vol 17, pg 259-63, 2008)
    Pukk-Harenstam, K.
    Ask, J.
    Brommels, M.
    Thor, J.
    Penaloza, R. V.
    Gaffney, F. A.
    POSTGRADUATE MEDICAL JOURNAL, 2009, 85 (1000) : 69 - 73
  • [8] ‘I no longer worry about money for transport to the health centre’ - economic empowerment of caregivers of children living with HIV through Village Savings and Loan Associations: experiences and lessons from the 'Towards an AIDS Free Generation Program in Uganda (TAFU)’
    Joseph Rujumba
    Carmen Roebersen
    Susan Namara
    Richard Ochen
    Sharon Eva Ahumuza
    Allen Tushabe
    Mathias Akugizibwe
    David Bitira
    Innocent Mwesigye
    Stella Kentusi
    Henry Zakumumpa
    Japheth Kwiringira
    Merian Natukwatsa Musinguzi
    BMC Health Services Research, 25 (1)