Secure E-Commerce Transactions for Multicast Services
Anil Kumar Venkataiahgari, John William Atwood, Mourad Debbabi · 2006
All e-commerce environments require support for security properties such as authentication, authorization, data confidentiality, and non-repudiation. E-commerce protocols such as SSL, TLS, and SET offer security for e-transactions, but they are specific to the unicast (point-to-point) environment. They cannot be directly extended to provide security for multicast (point-to-multipoint) sessions. Multicast data transmission provides significant network resource savings for applications such as audio/video streaming, news broadcast services and software distribution. However, security is required to prevent theft, and to ensure revenue generation from authorized recipients. We have designed the secure e-commerce transactions for multicast services (SETMS) architectural framework, to secure e-commerce sessions for multicast environments. The SETMS framework provides authentication of host through the HIP protocol, authorization of subscriber and his/her e-payments through a variant of the 2KP protocol, a procedure to account for the subscriber's resource consumption, and support for non-repudiation of principal parties through PKI. The SETMS framework has been formally validated using the AVISPA tool