Lightweight security primitives for E-commerce

被引:0
|
作者
Matias, Y [1 ]
Mayer, A [1 ]
Silberschatz, A [1 ]
机构
[1] AT&T Bell Labs, Lucent Technol, Murray Hill, NJ 07974 USA
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Emerging applications in electronic commerce often involve very low-cost transactions, which execute in the context of ongoing, extended client-server relationships. For example, consider a web-site (server) which offers repeated authenticated personalized stock quotes to each of its subscribers (clients). The value of a single transaction (e.g., delivery of a web-page with a customized set of quotes) does not warrant the cost of executing a handshake and key distribution protocol. Also, a client might not always use the same machine during such an extended relationship (e.g., a PC at home, a laptop on a trip). Typical transport/session-layer security mechanisms such as SSL and S-HTTP either require handshake/key distribution for each transaction or do not support client mobility. We propose a new security framework for extended relationships between clients and servers, based on persistent shared keys. We argue that this is a preferred model for inexpensive transactions executing within extended relationships. Our main contribution is the design and implementation of a set of lightweight application-layer primitives, for (1) generating and maintaining persistent shared keys without requiring a client to store any information between transactions and (2) securing a wide range of web-transactions (e.g., subscription, authenticated and/or private delivery of information, receipts) with adequate computational cost. Oar protocols require public key infrastructure only for servers/vendors, and its usage only once per client (upon first interaction).
引用
下载
收藏
页码:95 / 102
页数:8
相关论文
共 50 条
  • [1] A Lightweight Security Scheme in RFID Enabled E-Commerce Environments
    Godor, Gyozo
    Cserbak, Marton
    2008 IEEE 19TH INTERNATIONAL SYMPOSIUM ON PERSONAL, INDOOR AND MOBILE RADIO COMMUNICATIONS, 2008, : 2085 - 2089
  • [2] E-commerce security
    Gollmann, D
    COMPUTING & CONTROL ENGINEERING JOURNAL, 2000, 11 (03): : 115 - 118
  • [3] Security in e-commerce
    Müller, G
    LECTURES IN E-COMMERCE, 2001, : 149 - 162
  • [4] E-commerce security
    Gollmann, Dieter
    Elektron, 2001, 18 (03): : 44 - 47
  • [5] On the Security of e-commerce
    Razvan, Raducanu
    Eduard, Omusoru
    RECENT ADVANCES IN MATHEMATICS AND COMPUTERS IN BUSINESS, ECONOMICS, BIOLOGY & CHEMISTRY, 2010, : 171 - 174
  • [6] E-Commerce security
    Al-Slamy, Nada M. A.
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2008, 8 (05): : 340 - 344
  • [7] E-COMMERCE SECURITY ISSUES
    Ladan, Mohamad Ibrahim
    2014 INTERNATIONAL CONFERENCE ON FUTURE INTERNET OF THINGS AND CLOUD (FICLOUD), 2014, : 197 - 201
  • [8] Rethinking E-commerce security
    Oreku, George S.
    Li, Jianzhong
    INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE FOR MODELLING, CONTROL & AUTOMATION JOINTLY WITH INTERNATIONAL CONFERENCE ON INTELLIGENT AGENTS, WEB TECHNOLOGIES & INTERNET COMMERCE, VOL 1, PROCEEDINGS, 2006, : 223 - +
  • [9] A Survey of E-Commerce Security
    QIN Zhiguang
    Journal of Electronic Science and Technology, 2004, (03) : 173 - 176
  • [10] E-Commerce security issues
    Salehnia, A
    Pournaghshband, H
    ISSUES AND TRENDS OF INFORMATION TECHNOLOGY MANAGEMENT IN CONTEMPORARY ORGANIZATIONS, VOLS 1 AND 2, 2002, : 705 - 708