180 likes | 628 Views
Secure Electronic Transaction. Creating Debts Online with Confidence. SET Objectives. To encrypt critical information over the internet To separate the merchant from credit card information To link payment and order information. SET. Starring. Alice as the Cardholder
E N D
Secure Electronic Transaction Creating Debts Online with Confidence
SET Objectives • To encrypt critical information over the internet • To separate the merchant from credit card information • To link payment and order information
SET Starring • Alice as the Cardholder • Bob’s Beer Delivery as the Merchant • Visa as the Issuer • Wachovia as the Acquirer/Payment Gateway
Dual Signature How Bob can prove Alice paid for Natural Light and not Samuel Adams
PIMD PI H E kra DS POMD H || OI H OIMD Dual Signature Creation
! = How Bob Uses the DS DS = Ekra[ H( H(PI) || H(OI) ) ] • DS • PIMD • OI Ekua [ Ekra[ H( H(PI) || H(OI) ) ] ] H( H(PI) || H(OI) ) H( PIMD || H(OI) )
! = How Wachovia Uses the DS DS = Ekra[ H( H(PI) || H(OI) ) ] • DS • PI • OIMD Ekua [ Ekra[ H( H(PI) || H(OI) ) ] ] H( H(PI) || H(OI) ) H( H(PI) || OIMD )
Payment Processing • Purchase Request • Alice to Bob’s Beer Delivery • Payment Authorization • Bob’s Beer Delivery to Wachovia • Wachovia to Visa
Sent on by Bob’s Beer Delivery to Wachovia (Money Related) Contains Key To Decrypt Dual Sig (KPUB-Alice ) Used by Bob’s Beer Delivery (Order Related) From Alice To Bob’s Beer PIMD + Order Info + Dual Sig + Alice’s Cert. + + Dig Envelope
Payment Processing • Purchase Request • Alice to Bob’s Beer Delivery • Payment Authorization • Bob’s Beer Delivery to Wachovia • Wachovia to Visa
Sent on by Bob’s Beer Delivery to Wachovia (Money Related) Contains Key To Decrypt Dual Sig (KPUB-Alice ) Used by Bob’s Beer Delivery (Order Related) From Alice To Bob’s Beer PIMD + Order Info + Dual Sig + Alice’s Cert. + + Dig Envelope
From Alice Through Bob To Wachovia Money Info Encrypted Using Symmetric Key + Symmetric Key Encrypted Using Wachovia’s Public Key Dig Envelope
KS Bob’s Beer To Wachovia Payment Info E Dual Sig OIMD Temporary Symmetric Key Generated by Alice
KS KPUB-Wachovia Digital Envelope E Dig Envelope
D Payment Info KPRI-Wachovia Dual Sig OIMD KS KS D Obtaining The Payment Info Dig Envelope
SET Interoperability • Software development on SET protocol • Brokat, Entrust, Globeset, GTE, IBM, TrinTech, Verisign • SET costs • Software development • Hardware and runtime increases with high volume of transactions
Conclusion • Non-repudiation • Inherited credit card risks • Not widely used