• DocumentCode
    1220910
  • Title

    A flexible payment scheme and its role-based access control

  • Author

    Wang, Hua ; Cao, Jinli ; Zhang, Yanchun

  • Author_Institution
    Univ. of Southern Queensland, Toowoomba, Qld., Australia
  • Volume
    17
  • Issue
    3
  • fYear
    2005
  • fDate
    3/1/2005 12:00:00 AM
  • Firstpage
    425
  • Lastpage
    436
  • Abstract
    This work proposes a practical payment protocol with scalable anonymity for Internet purchases, and analyzes its role-based access control (RBAC). The protocol uses electronic cash for payment transactions. It is an offline payment scheme that can prevent a consumer from spending a coin more than once. Consumers can improve anonymity if they are worried about disclosure of their identities to banks. An agent provides high anonymity through the issue of a certification. The agent certifies reencrypted data after verifying the validity of the content from consumers, but with no private information of the consumers required. With this new method, each consumer can get the required anonymity level, depending on the available time, computation, and cost. We use RBAC to manage the new payment scheme and improve its integrity. With RBAC, each user may be assigned one or more roles, and each role can be assigned one or more privileges that are permitted to users in that role. To reduce conflicts of different roles and decrease complexities of administration, duty separation constraints, role hierarchies, and scenarios of end-users are analyzed.
  • Keywords
    Internet; authorisation; bank data processing; certification; cryptography; data integrity; electronic money; purchasing; transaction processing; Internet purchases; electronic cash; electronic payment transactions; offline payment scheme; role-based access control; Access control; Access protocols; Certification; Computational efficiency; Computer Society; Cryptography; Databases; Internet; Security; World Wide Web;
  • fLanguage
    English
  • Journal_Title
    Knowledge and Data Engineering, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1041-4347
  • Type

    jour

  • DOI
    10.1109/TKDE.2005.35
  • Filename
    1388251