Formal analysis of card-based payment systems in mobile devices

Formal analysis of card-based payment systems in mobile devices
复制标题

移动设备中基于卡的支付系统的形式分析

DOI:
--
复制
发表时间:
2006
期刊:
Australasian Computer Science Week
影响因子:
--
通讯作者:
J. Cho
J. Cho
中科院分区:
--
文献类型:
--
作者:
Vijayakrishnan Pasupathinathan;J. Pieprzyk;Huaxiong Wang;J. Cho

文献摘要

被引文献

相似文献

为了在使用移动的设备进行电子交易时提供卡保持器认证,VISA和MasterCard独立地提出了两种电子支付协议:Visa 3D Secure和MasterCard Secure Code。这些协议使用预先注册的密码来提供卡保持器身份验证和安全套接字层/传输层安全性(SSL/TLS),以实现有线网络上的数据机密性以及无线设备和无线应用协议(WAP)网关之间的无线传输层安全性(WTLS)。本文提出了我们的安全性分析所提出的协议,使用形式化的方法工具:Casper和FDR 2。我们还强调了拟议协议中有关支付安全的问题。
To provide card holder authentication while they are conducting an electronic transaction using mobile devices, VISA and MasterCard independently proposed two electronic payment protocols: Visa 3D Secure and MasterCard Secure Code. The protocols use pre-registered passwords to provide card holder authentication and Secure Socket Layer/ Transport Layer Security (SSL/TLS) for data confidentiality over wired networks and Wireless Transport Layer Security (WTLS) between a wireless device and a Wireless Application Protocol (WAP) gateway. The paper presents our analysis of security properties in the proposed protocols using formal method tools: Casper and FDR2. We also highlight issues concerning payment security in the proposed protocols.