A resilient access control scheme for secure electronic transactions

Jong‐Hyeon Lee · 1998

T here have been m any studies of the m anagem entofpersonalsecrets such as P IN codes,passw ord s, etc.,in access con trol m ech an ism s. T h e leakage of personal secrets is one of the m ost significant problem s in access con trol.Tored u ce su ch risk s,w e su ggest a w ay ofau th en tica ting custom ers w ithout transferring explicit custo m e r se cre ts. F u rth e rm o re, w e g ive a secure online transaction schem e based on our access contro l m e ch a n ism . N eedham gave an exam ple ofPersonalIdentification N um ber (PIN )m anagem ent for banking system s [N ee97]that presented a w ay to control P IN codes. It inspired us to develop an access con trol m od el for electronictransactions w hich enforces a strict role definition for personal secret generation and m aintenance. W e extend it toapaymentmodel. Our schem e provides enhanced privacy for custom ers, non-repudiation of originfo r th e cu sto m e r o rd e r a n d p a y m e n t tra n sa ction s, an d p rotection from...

Read the paper · More papers on PaperTik