Web Security: Web Security:
Secure Electronic Transaction Secure Electronic Transaction
Cunsheng Cunsheng Ding Ding HKUST, Hong Kong, CHI NA HKUST, Hong Kong, CHI NA
Web Security: Web Security: Secure Electronic Transaction Secure - - PowerPoint PPT Presentation
Web Security: Web Security: Secure Electronic Transaction Secure Electronic Transaction Cunsheng Cunsheng Ding Ding HKUST, Hong Kong, CHI NA HKUST, Hong Kong, CHI NA Secure Elect ronic Transact ions An applicat ion-layer secur it y
Cunsheng Cunsheng Ding Ding HKUST, Hong Kong, CHI NA HKUST, Hong Kong, CHI NA
2
consist ing of a set of pr ot cols.
I nt er net .
– Mast erCard, Visa, I BM, Microsof t , Net scape, RSA, Terisa and Verisign
– described in 3 books, wit h 971 pages1
3
4
– Conf ident ialit y of inf ormat ion – I nt egr it y of dat a – Car dholder account aut hent icat ion – Mer chant aut hent icat ion
5
Acquir er f or payment pr ocessing.
aut hor it y t hat issues X.509v3 public-key cer t if icat es f or car dholder s, mer chant s, and payment gat eways.
6
7
a cer t if icat e f r om t he CA
goods or service
8
int ended f or t wo dif f er ent r ecipient s
cust omer’s cr edit car d number
any disput es if required
9
PI OI H H D H PIMD POMD OIMD
Dual Signature
Kd
PI = Payment Information OI = Order Information H = Hash function(SHA-1) || = Concatenation || PIMD = PI message digest OIMD = OI message digest POMD = Payment order message digest D = Decryption = Customer’s private signature key (c) (c)
Kd
10
Mer chant Cer t if icat e, init ial r esponse Or der & Payment I nf or m. I nit ial r equest (I D, nonce)
Verif y merchant Verif y Cust omer 1.2 1.3 1.4 1.5 1.1
11
I nitial Request
cust omer is using.
request / response pair f or ident if ying t his pair.
t imeliness. I nitial Response
– The nonce f rom t he cust omer, anot her nonce f or t he cust omer t o ret urn in t he next message. – A t ransact ion I D.
cert if icat e.
exchange cert if icat e.
12
Remar k: The det ailed ver if icat ion depends
algor it hms
13
Request message
E E
Digital Envelope OI PIMD Cardholder certificate + + + + + + + Dual Signature Passed on by merchant to payment gateway PI Dual Signature OIMD
Ks K e
Received by merchant
Ks = Temporary symmetric key Ke = Bank’s public key-exchange key
(b)
(b)
E = Encryption (RSA for asymmetric; DES for symmetric)
14
– OI message digest
– it cont ains secret key
– PI message digest
15
Digital Envelope OI PIMD Cardholder certificate + + + + + Dual Signature Request message Passed on by merchant to payment gateway
||
E H H
Compare
Ke
POMD POMD OIMD E = Encryption (RSA) Ke = Customer’s public key
(c)
(c)
16
Aut hor izat ion Request
17
Mer chant ==> Payment Gat eway
– OI message digest
– t ransact ion I D, signed wit h merchant ’s privat e key, and encrypt ed wit h a session key generat ed by t he merchant .
– session key encrypt ed wit h t he gat eway’s public key.
Cardholder’s cert if icat e
18
block t o obt ain t he session key and t hen decrypt s t he aut horizat ion block.
aut horizat ion block.
payment block.
merchant mat ches t hat in t he PI received (indirect ly) f rom t he cust omer.
19
Request s and receives an aut horizat ion f rom t he issuer
20
Aut horizat ion Response
21
– aut horizat ion block, signed wit h gat eway’s privat e key and encrypt ed wit h a session key generat ed by t he Gat eway. – An envelope, t he session key encrypt ed wit h t he merchant ’s public key.
– This inf ormat ion will be used t o ef f ect payment lat er. – I t has t he same f orm as t he aut horizat ion-relat ed inf ormat ion above.
22
– Merchant delivers goods af t er get t ing t he aut horizat ion response f rom t he payment gat eway.
capt ur e
– involves all part ies. – Det ails omit t ed.
23
I nt ernet secure.
– That bot h part ies are "genuine". – That t he cust omer is prot ect ed against misuse
– That alt erat ions cannot be made t o orders wit hout being discovered. – That orders can only be read by t he cust omer and t he company concerned. – That payment inf ormat ion can only be read by t he acquirer and t he cust omer.
24
Secur it y 3/ e, Pear son, 2003
Commer ce. Cambr idge, MA: O’Reilly and Associat es, 1997.
Elect r onic Commer ce, Upper Saddle River, NJ : Prent ice Hall, 1999.