Title :
CONSEPP: CONvenient and secure electronic payment protocol based on X9.59
Author :
Levi, Albert ; Koç, Çetin Kaya
Author_Institution :
Dept. of Electr. & Comput. Eng., Oregon State Univ., Corvallis, OR, USA
Abstract :
The security of electronic payment protocols is of interest to researchers in academia and industry. While the ultimate objective is the safest and most secure protocol, convenience and usability should not be ignored, or the protocol may not be suitable for large-scale deployment. Our aim is to design a practical electronic payment protocol which is both secure and convenient. ANSI X9.59 standard describes secure payment objects to be used in electronic payment in a convenient and secure way. It has many useful convenience features for large-scale consumer market deployment, the best being the elimination of consumer certificates. Consumer public keys are stored in account records at financial institutions; the digital signatures issued by consumers are verified by financial institutions. Encryption is deliberately not provided by X9.59. We propose a new Internet e-payment protocol, namely CONSEPP (CONvenient and Secure E-Payment Protocol), based on the account authority model of ANSI X9.59 standard. CONSEPP is the specialized version of X9.59 for Internet transactions (X9.59 is multi-purpose). It has some extra features on top of the X9.59 standard. X9.59 requires merchant certificates; in CONSEPP we propose a lightweight method to avoid the need for merchant certificates. Moreover, we propose a simple method for secure shopping experience between merchant and consumer. Merchant authentication is embedded in the payment cycle. CONSEPP aims to use current financial transaction networks, like VisaNet, BankNet and ACH networks, for communications among financial institutions. No certificates (in the classical sense) or certificate authorities exist in CONSEPP. Convenience is not traded for security; basic security requirements are fulfilled in the payment authorization cycle without extra messaging and significant overhead.
Keywords :
Internet; electronic commerce; security of data; transport protocols; ACH networks; ANSI X9.59 standard; BankNet; CONSEPP; Convenient and Secure Electronic Payment Protocol Based on X9.59; Internet e-payment protocol; Internet transactions; VisaNet; account authority model; consumer public keys; digital signatures; e-commerce; electronic commerce; electronic payment protocols; financial institutions; merchant authentication; payment authorization cycle; payment cycle; secure payment objects; secure shopping experience; ANSI standards; Consumer electronics; Electronics industry; Industrial electronics; Internet; Large-scale systems; Protocols; Public key; Security; Usability;
Conference_Titel :
Computer Security Applications Conference, 2001. ACSAC 2001. Proceedings 17th Annual
Print_ISBN :
0-7695-1405-7
DOI :
10.1109/ACSAC.2001.991544