首页> 外文会议>International Conference on Security and Cryptography >Secure Protocol for Financial Transactions Using Smartphones - SPFT Formally Proved by AVISPA
【24h】

Secure Protocol for Financial Transactions Using Smartphones - SPFT Formally Proved by AVISPA

机译:使用智能手机 - 使用智能手机 - SPFT由Avispa证明的安全协议

获取原文

摘要

Smartphones are overpowering the IT world by rising as a prerequisite for other technologies. Emerging technology paradigms such as Cloud computing, web data services, online banking and many others are revamping them as compatibility to smartphones. Banking is a vital and critical need in daily life. It involves routine financial transactions among sellers, buyers and third parties. Several payment protocols are designed for mobile platforms which involve hardware tokens, PIN, credit cards, ATMs etc. for secure transactions. Many of them are not properly verified and have hidden flaws. Numerous vulnerabilities have been found in existing solutions which raise a big question about the defense capability of smartphones to protect user's data. In this paper we propose a secure payment protocol for smartphones without using any hardware token. It implicates bank as a transparent entity and users rely on a payment gateway to mark a successful transaction. Suggested protocol uses symmetric keys, Digital certificates X.509, and two-factor authentication to make a secure financial deal. To prove the secrecy and authentication properties of the protocol we have formally verified it by AVISPA.
机译:智能手机通过作为其他技术的先决条件来推翻IT世界。新兴技术范式,如云计算,网络数据服务,网上银行和许多其他人正在将其改造为与智能手机的兼容性。银行业务在日常生活中是至关重要的。它涉及卖方,买方和第三方之间的日常金融交易。若干付款协议专为移动平台而设计,涉及硬件令牌,PIN,信用卡,ATMS等。其中许多没有得到适当验证并具有隐藏的缺陷。在现有解决方案中发现了许多漏洞,这提出了关于智能手机的防御能力来保护用户数据的大问题。在本文中,我们为智能手机提出了安全的付款协议,而无需使用任何硬件令牌。它将银行视为透明实体,用户依赖支付网关来标记成功的交易。建议的协议使用对称密钥,数字证书X.509和双因素认证,以制定安全的金融交易。为了证明“协议的保密性和身份验证属性”,我们已由Avispa正式验证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号