A Secure-Cookie Recipe for Electronic Transactions
نویسنده
چکیده
Since there is no concept of a session in HTTP, Web servers and browsers use cookies to capture information for subsequent communications on the Web, thus providing continuity and state across HTTP connections. Technically, cookies can be used to support electronic transactions on the Web, holding users' credit card information. However, it is insecure to store and transmit sensitive information in cookies, because cookies are stored and transmitted in clear text, which is readable and easily forged. In this paper, we describe a recipe of secure cookies for electronic transactions on the Web. A user's credit card information is contained in a set of secure cookies and transmitted to the corresponding Web servers. Therefore, these servers can trust the credit card information in the cookies after cookie-veri cation procedures and use it for electronic transactions. The technology is transparent to users and applicable to existing Web servers and browsers.
منابع مشابه
A secure cookie scheme
Cookies are the primary means for web applications to authenticate HTTP requests and to maintain client states. Many web applications (such as those for electronic commerce) demand a secure cookie scheme. Such a scheme needs to provide the following four services: authentication, confidentiality, integrity, and anti-replay. Several secure cookie schemes have been proposed in previous literature...
متن کاملSmart Certi cates: Extending X.509 for Secure Attribute Services on the Web
An attribute is a particular property of an entity, such as a role, access identity, group, or clearance. If attributes are provided integrity, authentication, and con dentiality, Web servers can then trust these secure attributes and use them for many purposes, such as access control, authorization, authentication, and electronic transactions. In this paper, we present a comprehensive approach...
متن کاملSecure Authentication Mechanism in Mobile Internet Protocol Version 6
This paper presents a secure authentication method for Mobile IPv6. As a default IPsec is used for secure signaling messages between the Mobile Node and other agents in Mobile IPv6 networks. Mobile IPv6 message transactions include the Binding Updates and Acknowledgement messages as well. We propose a new mechanism for securing Mobile IPv6 signaling between Mobile Node and other agents. The pro...
متن کاملSmart Certi cates : Extending X . 509 for Secure Attribute Services on the WebJoon
An attribute is a particular property of an entity, such as a role, access identity, group, or clearance. If attributes are provided integrity, authentication, and conndentiality, Web servers can then trust these secure attributes and use them for many purposes, such as access control, authorization, authentication, and electronic transactions. In this paper, we present a comprehensive approach...
متن کاملThe Nature and Ethical Effects of Options in Electronic Transactions
Background: Electronic transactions are another form of transactions that are done through electronic tools such as mobile phones, computers, tablets, etc. Considering the synchronization of Iranchr('39')s economic system with the world and meeting the needs of the day, ensuring the correct conclusion of electronic transactions with the correct and ethical use of options is explored. The presen...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 1999