130 likes | 146 Views
Commerce and Financial Transaction Security Over the Internet. Dave Crocker Brandenburg Consulting dcrocker@brandenburg.com +1 408 246 8253 www.brandenburg.com. What we will cover. Architecture Channel Object Commerce Trading Payment. Object. Channel. Secure. Email Secure.
E N D
Commerce and Financial Transaction Security Over the Internet Dave Crocker Brandenburg Consulting dcrocker@brandenburg.com +1 408 246 8253www.brandenburg.com
What we will cover • Architecture • Channel • Object • Commerce • Trading • Payment
Object Channel Secure Email Secure Web Secure My object Web Server MTA Email FTP Web Web Server MTA Email Secure Secure My object My object My object My object Where to put security? My object
Channel security IPSEC IP-level labeling Kerberos (MIT) Third-party service S-KEY/OTP Pairwise login SSL/TSL Client-server link SASL Scheme selection
PGP PGP, Inc. Qualcomm Years of use Significant installed base Informal CA scheme w/server S/MIME RSA DSI Netscape, Microsoft No usage history Sudden large installed base Formal CA scheme w/ server Object contenders
Phases Shopping Searching Negotiating Terms Buying Instrument Paying Exchange
Open Trading Protocol • OTP Consortium • Functions • Authentication • Deposit • Purchase • Refund • Withdrawal • Value Exchange
Payment system model Risk Management... Clearing House Buyer Issuing Bank 16+4 Acquiring Bank Merchant M. Rose, FV
Scheme “Clear” Just trust the net... Easy to capture and replay. Buyer 16+4 in the clear! Clearing House Merchant
Scheme “ID” Still trust the net, until the next statement... Easy to capture and replay. Buyer 16+4 ID Clearing House ID Merchant 16+4
Scheme “ID confirm” 16+4 Buyer ID Clearing House ID Confirm Merchant ID Each transaction confirmed. Requires mildly safe user account.
Scheme “Secure link” Same a telephone, but encrypt over Internet. Merchant gets number. Is merchant safe?? Buyer Encrypted 16+4 Clearing House Merchant 16+4
Scheme “Mediated” Only banks sees data in clear. Limited points of attack. Buyer Encrypted 16+4 Encrypted 16+4 Clearing House Merchant