首页> 外文会议>International Conference on HCI for Cybersecurity, Privacy and Trust;International Conference on Human-Computer Interaction >Security Analysis of Transaction Authorization Methods for Next Generation Electronic Payment Services
【24h】

Security Analysis of Transaction Authorization Methods for Next Generation Electronic Payment Services

机译:下一代电子支付服务交易授权方法的安全分析

获取原文

摘要

Real-world and ubiquitous human-computer interactions require payment processes that have to be instant, convenient and interoperable. However, these functional requirements are in opposition to one of the most significant non-functional requirement: security of the payment process. A number of various attacks on confidentiality of payment or payer data, integrity, authenticity and non-repudiation of payment transaction, as well as on availability of the payment service are reported. Next generation electronic payment services utilize wide range of payment authorization methods. Security analysis of authorization methods described in this paper includes four sequential phases. The first one is identification of relevant authorization methods related to payment authorization in various scenarios. The second one is identification of classes of vulnerabilities and threats that are, or potentially can be, related to transaction authorization processes. The third phase comprises analysis of risks resulting from possible impact of the threats on the authorization methods. The fourth phase covers identification of all types of countermeasures that can be applied against risks identified in the previous phase. The result of presented work can be useful in a number of risk analysis scenarios. Especially in those, where security of composed system is analyzed, which means a system that supports a number of assets, electronic payments methods, and countermeasures or security controls in various scenarios when they are simultaneously used and interact with each other.
机译:现实世界和无处不在的人机交互需要支付流程,必须即时,方便和可互操作。然而,这些功能要求与最重要的非功能要求之一相反:付款流程的安全性。报告了许多关于支付或支付者数据的机密性,完整性,真实性以及支付交易的非拒绝的各种攻击,以及支付服务的可用性。下一代电子支付服务利用广泛的付款授权方法。本文中描述的授权方法的安全性分析包括四个连续阶段。第一个是识别与各种方案中的支付授权有关的相关授权方法。第二个是识别漏洞和威胁的阶级,或者可能是与交易授权过程有关的威胁。第三阶段包括对可能影响威胁对授权方法产生的风险的分析。第四阶段涵盖了可以针对先前阶段所识别的风险应用的所有类型的对策。所呈现的工作结果可以在许多风险分析方案中有用。特别是在分析所属系统的安全性的那些中,这意味着当它们同时使用和交互时,在各种场景中支持许多资产,电子支付方法和对策或安全控制的系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号