触及 Apple Wallet 遗漏的卡片:在 iOS 上直接通过 NFC 获取 PRO100、HUMO 和 UZCARD 支付卡
Reaching the Cards Apple Wallet Leaves Behind: Direct NFC Acquisition of PRO100, HUMO and UZCARD Payment Cards on iOS
AI总结:
针对苹果未覆盖的中亚支付卡,提出基于 Core NFC 的应用层卡片捕获方法,可读取 PAN 和有效期,并给出系统工作流与评估协议。
AI中文摘要:
通过手机进行非接触式支付在许多市场已成为日常,但这种便利的分布并不均衡。苹果目前将哈萨克斯坦列为支持 Apple Pay 的市场,但未包含乌兹别克斯坦、吉尔吉斯斯坦、塔吉克斯坦或土库曼斯坦。在乌兹别克斯坦,HUMO 和 UZCARD 是两个国家银行间零售卡系统,两者均包含非接触式卡产品。本文描述了一种针对支持 NFC 的 iPhone 上测试的 PRO100、HUMO 和 UZCARD 卡的应用层卡片捕获方法。利用 Core NFC,读取器打开一个标签会话,在必要时选择一个应用,并从返回的数据中恢复主账号(PAN)和有效期。难点在于经验性的部分:识别在测试卡上有效的 AID,以及解码特定于卡片生成的响应布局。实现后来通过混合解析路径进行了加固,该路径在存在 BER-TLV/EMV 字段时优先使用这些字段,并将观察到的偏移量仅作为传统回退方案。本文还给出了系统级工作流程、威胁模型、明确的故障处理、平台比较以及可复现的评估协议。本文并未声称相同行为在每款 iPhone/iOS 组合、iPadOS 或 macOS 上,或在未来的 Core NFC 政策下均保持不变。该方法捕获注册数据;它不模拟卡片、不授权支付,也不将 NFC 读取视为所有权的证明。
英文摘要:
Contactless payment from a phone has become routine in many markets, but the convenience is unevenly distributed. Apple currently lists Kazakhstan among supported Apple Pay markets, but not Uzbekistan, Kyrgyzstan, Tajikistan or Turkmenistan. In Uzbekistan, HUMO and UZCARD are the two national interbank retail card systems, and both include contactless card products. This paper describes an application-level card-capture method for tested PRO100, HUMO and UZCARD cards on NFC-capable iPhones. Using Core NFC, the reader opens a tag session, selects an application when necessary, and recovers the primary account number (PAN) and expiry date from the returned data. The difficult parts were empirical: identifying AIDs that worked on the tested cards and decoding card-generation-specific response layouts. The implementation was later hardened around a hybrid parsing path that prefers BER-TLV/EMV fields when present and keeps the observed offsets only as a legacy fallback. The paper also gives a system-level workflow, a threat model, explicit failure handling, a platform comparison, and a reproducible evaluation protocol. No claim is made that the same behavior is available unchanged on every iPhone/iOS combination, on iPadOS or macOS, or under future Core NFC policy. The method captures registration data; it does not emulate a card, authorize a payment, or treat an NFC read as proof of ownership.