The Security Requirement for off-line E-cash system based on IC Card
Haeryong Park, Kilsoo Chun, Seung-Ho Ahn · 2006
An off-line E-cash system is presented that offers appreciably greater security and better privacy than currently considered E-cash system with similar functionality. Most off-line E-cash systems use the temper-resistant IC Card which controls an E-cash issued by the Card Issuer. Off-line E-cash system based on IC Card has the threats of overspending, double spending, forgery E-cash, altering/eavesdropping transaction contents, etc. To prevent the above threats, there have been a lot of technical discussions of the security requirements for theoretical off-line E-cash protocols based on IC Card. However, there has been little attention paid to the security requirements for practical off-line E-cash system based on IC Card including entity authentication, key management, implementation of cryptographic algorithm, etc. Thus, this paper describes the security requirements for cryptographic algorithms, integrity for implementation of cryptographic algorithm, authentication module, key management, and E-cash protocols.