DocumentCode :
2268260
Title :
On the design of secure electronic payment schemes for Internet
Author :
Varadharajan, Vijay ; Mu, Yi
Author_Institution :
Distributed Syst. & Network Security Res. Unit, Univ. of W. Sydney, Kingswood, NSW, Australia
fYear :
1996
fDate :
9-13 Dec 1996
Firstpage :
78
Lastpage :
87
Abstract :
Considers the design of secure electronic credit card based payment schemes for the Internet, and reveals some of the issues that have not been adequately addressed in the proposed protocols to date. This paper proposes additional mechanisms that need to be incorporated as part of the design phase of the scheme to deal efficiently with the disputes that can arise. The design methods described in this paper are applicable to a range of protocols, including iKP (Internet Kaufmannisch Protokoll), STT (Secure Transaction Technology) and SEPP (Secure Electronic Payment Protocol). Based on this discussion, the paper goes on to propose an improved payment scheme and protocol. The new protocol, referred to as the permission-based payment (PBP) protocol, provides a fair treatment of both the client and the merchant involved in the transaction. It separates the purchase request phase from the payment phase, thereby increasing the ability to handle certain class of disputes more efficiently. It removes the need to store the secret private key at the client´s machine or the need for a smart card device. This is important as one cannot assume that all the clients connected to the Internet have smart card readers attached to them. The new protocol makes simpler assumptions about the environment, thereby making the scheme practical for securing commercial electronic credit card transactions
Keywords :
EFTS; Internet; business data processing; protocols; security of data; Internet; PBP protocol; SEPP; STT; commercial electronic credit card transactions; disputes; iKP; payment phase; permission-based payment protocol; purchase request phase; secret private key; secure electronic payment schemes; Australia; Consumer electronics; Credit cards; Electronic commerce; Explosions; Explosives; IP networks; Information security; Protocols; Web and internet services;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Security Applications Conference, 1996., 12th Annual
Conference_Location :
San Diego, CA
ISSN :
1063-9527
Print_ISBN :
0-8186-7606-X
Type :
conf
DOI :
10.1109/CSAC.1996.569674
Filename :
569674
Link To Document :
بازگشت