Modified SET protocol for mobile payment
Sabrina M. Shedid · Networked Computing and Advanced Information Management · 2010
The wide spread of using handheld devices offers an opportunity for mobile devices to be used as a universal payment method. However, some issues hinder the widespread acceptance of Mobile Payment (MP) such as: privacy protection, limited capability of mobile devices, limited bandwidth of wireless networks and etc. In Ecommerce Payment (EP), Secure Socket Layer (SSL) protocol has been used to establish a secure channel between customer and merchant to secure the payment and the order information. SSL has some disadvantages regarding customer privacy where the customer payment information is revealed to the merchant. Secure Electronic Transaction (SET) has resolved SSL protocol disadvantages by splitting the order message into: 1) Order information which is revealed to merchant, 2) Payment information which is revealed to Payment Gateway (PG). Both SSL and SET assume the existence of Public Key Infrastructure (PKI) where extensive computation is carried out. The same situation happens in case of MP, where the same protocols in MP are inadequate to guarantee the privacy. In this paper, a Modified Secure Electronic Transaction (MSET) protocol is proposed to minimize the extensive computations of SET protocol through replacing time consuming public key encryption and decryption algorithms by symmetric key cryptography.