Comparative Security Analysis of Apple Pay and Google Wallet: Strengths, Weaknesses, and Threats -- 2025 35th IEEE International Conference Radioelektronika (RADIOELEKTRONIKA25) Academic Article uri icon

Abstract

  • Mobile payment platforms, such as Apple Pay and Google Wallet, have revolutionized financial transactions through Near Field Communication (NFC), tokenization, and biometric authentication. Although both systems implement robust security measures, their architectures introduce distinct security trade-offs. Apple Pay's Secure Element ensures hardware-isolated token storage, providing a high level of protection against malware and unauthorized access. In contrast, Google Wallet relies on Host Card Emulation (HCE), allowing for broader device compatibility but increasing the attack surface due to its software-based token storage and cloud dependencies. This paper conducts a comparative security analysis of these two platforms, identifying key vulnerabilities, including NFC relay attacks, unauthorized token retrieval, backend authentication weaknesses, and cloud-based risks. In addition, we explore SIM-swapping attacks, phishing schemes, and malware threats targeting mobile payments. By examining design challenges, architectural choices, and security mechanisms, we assess trade-offs between hardware-and software-based security models.

Publication Date

  • 2025-05-01

Published In