Securing on-line credit card payments without disclosing privacy information

نویسندگان

  • Jing-Jang Hwang
  • Tzu-Chang Yeh
  • Jung-Bin Li
چکیده

Two revisions of the original Secure Electronic Transaction (SET) protocol are proposed to conceal cardholders’ identities in the electronic marketplace in which cardholders’ trust for banks can be reduced to a minimum. Constrained by being extensions of the existing card payment networks to the Internet, most on-line credit card payment schemes in use or proposed in recent papers assume the sensitive card information could be disclosed to all the participating banks. The assumption used to work well in traditional credit card payments before. However, negative impacts such as banking scandals, closure programs due to poor management, and security problems with Internet banking are all undermining cardholders’ trust in banks. The issuer is the trusted bank selected by the cardholder, but the acquirer is not. To reveal the cardholder’s sensitive card information to every possible acquirer implies potential risk. Based on the need-to-know principle, the two revisions are proposed to relax the assumption mentioned above. In our solutions, the sensitive card information is well protected along the way and can be extracted only by the issuer. A cardholder needs only to select a trustworthy issuer, instead of worrying about the possible breakdowns of every involved acquirer. The cost to achieve our more secure schemes demands only minor information modifications on the legacy system. D 2002 Elsevier Science B.V. All rights reserved.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Towards Pseudonymous e-Commerce

The lack of privacy is one of the main reasons that limits trust in e-commerce. Current e-commerce practice enforces a customer to disclose her identity to the e-shop and the use of credit cards makes it straightforward for an e-shop to know the real identity of its customers. Although there are some payment systems based on untraceable tokens, they are not as widely used as credit cards. Furth...

متن کامل

Social Simulation of Commercial and Financial Behaviour for Fraud Detection Research

We present a social simulation model that covers three main financial services: Banks, Retail Stores, and Payments systems. Our aim is to address the problem of a lack of public data sets for fraud detection research in each of these domains, and provide a variety of fraud scenarios such as money laundering, sales fraud (based on refunds and discounts), and credit card fraud. Currently, there i...

متن کامل

Optimizing Consumer Credit Markets and Bankruptcy Policy

This Article explores the relationship between consumer credit markets and bankruptcy policy. In general, I argue that the causative relationships running between borrowing and bankruptcy compel a new strategy for policing the conduct of lenders and borrowers in modern consumer credit markets. The strategy must be sensitive to the role of the credit card in lending markets and must recognize th...

متن کامل

Recent Developments in the Credit Card Market and the Financial Obligations Ratio

Over the past fifteen years, U.S. households in the aggregate have devoted an increasing share of their after-tax income to the payment of financial obligations. Much of the increase is attributable to a rise in the level of credit card debt, which has raised the share of households’ aggregate after-tax income that is devoted to credit card payments. In turn, the rising share of credit card deb...

متن کامل

Comparing Different Methodologies Used To Ensure the Security of RFID Credit Card: A Comparative Analysis

The use of Radio Frequency Identification (RFID) advancement is turning out to be rapidly transversely over an extensive variety of business undertakings. Engineers apply the development not simply in customary applications, for instance, asset or stock after, also in security organizations, electronic travel papers and RFID-embedded card. In any case, RFID development moreover brings different...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • Computer Standards & Interfaces

دوره 25  شماره 

صفحات  -

تاریخ انتشار 2003