A security framework for card-based systems

被引:0
|
作者
Tsiounis, Y [1 ]
机构
[1] InternetCash Corp, New York, NY USA
来源
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The legal framework provided by the Electronic Signature Act, enacted to law as of October 1, 2000, has fueled the interest for digital signature-based payment transactions over the Internet. The bulk of formalization and security analysis to date on such secure payments has focused on creating new secure channels for existing credit or debit card systems (iKP and SET). But there has been no formal modeling, or an attempt to strengthen of the security of, the card systems themselves. In this paper we present a simple but formal communication and security model for all card-based payments, encompassing credit, debit acid pre-paid cards, and proceed to propose CardSec, a new family of card-based systems which can be proven secure under this model. In the process we also analyze the security of existing credit, debit and pre-paid card systems, both for Internet and for brick and mortar payments. We then present an efficient implementation of CardSec in the form of the InternetCash(TM) card system and analyze its security in detail. We take the opportunity to describe the InternetCash Payment Protocol (ICPP) which can be used for creating a secure channel between Transaction Processor and Customer for all Internet-bound transactions, thus acting as an alternative to iKP and SET, and offering more security than systems utilizing limited-use credit card numbers. We conclude with a discussion on pre-authorization, refunds and customer service issues.
引用
收藏
页码:210 / 231
页数:22
相关论文
共 50 条
  • [1] Enhancing the Security for Smart Card-Based Embedded Systems
    Kalyana Abenanth, G.
    Harish, K.
    Sachin, V.
    Rushyendra, A.
    Mohankumar, N.
    [J]. Lecture Notes on Data Engineering and Communications Technologies, 2022, 75 : 673 - 686
  • [2] An integrated framework for card-based production control systems
    Ryo Sato
    Yaghoub Khojasteh-Ghamari
    [J]. Journal of Intelligent Manufacturing, 2012, 23 : 717 - 731
  • [3] An integrated framework for card-based production control systems
    Sato, Ryo
    Khojasteh-Ghamari, Yaghoub
    [J]. JOURNAL OF INTELLIGENT MANUFACTURING, 2012, 23 (03) : 717 - 731
  • [4] Card-based security protects remote access
    不详
    [J]. COMMUNICATIONS NEWS, 1996, 33 (04): : 54 - 54
  • [5] A Novel Card-based Information Security Game Development on SNS
    Lim, Woo-Taek
    Yang, Moon-Bo
    Kim, Seong Baeg
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2013, 7 (06): : 127 - 136
  • [6] Smart card-based electronic card payment systems in the transportation industry
    Turban, E
    Brahm, J
    [J]. JOURNAL OF ORGANIZATIONAL COMPUTING AND ELECTRONIC COMMERCE, 2000, 10 (04) : 281 - 293
  • [7] Practical Card-Based Cryptography
    Mizuki, Takaaki
    Shizuya, Hiroki
    [J]. FUN WITH ALGORITHMS, 2014, 8496 : 313 - 324
  • [8] Card-Based Covert Lottery
    Graduate School of Information Sciences, Tohoku University, Sendai, Japan
    不详
    不详
    不详
    [J]. Lect. Notes Comput. Sci., 1600, (257-270):
  • [9] Are card-based systems effective for make-to-order production?
    [J]. 2016, Editura ASE Bucuresti (2016):
  • [10] Cobacabana (control of balance by card-based navigation): A card-based system for job shop control
    Land, Martin J.
    [J]. INTERNATIONAL JOURNAL OF PRODUCTION ECONOMICS, 2009, 117 (01) : 97 - 103