Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
skip to main content
10.5555/525080.884269acmconferencesArticle/Chapter ViewAbstractPublication PagesspConference Proceedingsconference-collections
Article

On two Proposals for On-line Bankcard Payments using Open Networks: Problems and Solutions

Published: 06 May 1996 Publication History

Abstract

Recently, two major bankcard payment instrument operators VISA and MasterCard published specifications for securing bankcard payment transactions on open networks for open scrutiny. (VISA: Secure Transaction Technology, STT; MasterCard: Secure Electronic Payment Protocol, SEPP.) Based on their success in operating the existing on-line payment systems, both proposals use advanced cryptographic technologies to supply some security services that are well-understood to be inadequate in open networks, and otherwise specify systems similar to today's private-network versions. In this paper we reason that when an open network is used for underlying electronic commerce some subtle vulnerabilities will emerge and the two specifications are seen not in anticipation of them. A number of weaknesses are found as a result of missing and misuse of security services. Missing and misused services include: authentication, non-repudiation, integrity, and timeliness. We identify problems and devise solutions while trying to keep the current successful working style of financial institutions being respected.

Cited By

View all
  • (1997)A calculus for cryptographic protocolsProceedings of the 4th ACM conference on Computer and communications security10.1145/266420.266432(36-47)Online publication date: 1-Apr-1997
  1. On two Proposals for On-line Bankcard Payments using Open Networks: Problems and Solutions

    Recommendations

    Comments

    Information & Contributors

    Information

    Published In

    cover image ACM Conferences
    SP '96: Proceedings of the 1996 IEEE Symposium on Security and Privacy
    May 1996
    ISBN:0818674172

    Sponsors

    Publisher

    IEEE Computer Society

    United States

    Publication History

    Published: 06 May 1996

    Check for updates

    Qualifiers

    • Article

    Contributors

    Other Metrics

    Bibliometrics & Citations

    Bibliometrics

    Article Metrics

    • Downloads (Last 12 months)0
    • Downloads (Last 6 weeks)0
    Reflects downloads up to 03 Feb 2025

    Other Metrics

    Citations

    Cited By

    View all
    • (1997)A calculus for cryptographic protocolsProceedings of the 4th ACM conference on Computer and communications security10.1145/266420.266432(36-47)Online publication date: 1-Apr-1997

    View Options

    View options

    Figures

    Tables

    Media

    Share

    Share

    Share this Publication link

    Share on social media