透過您的圖書館登入
IP:3.138.101.95
  • 期刊

具效率與可延遲驗證之一次性信用卡號付款機制

An Efficient One-Time Credit Card Payment Scheme with Delayed Verification

摘要


隨著網際網路上電子商務蓬勃發展,電子商務所仰賴的網路付費系統越來越重要。各式電子付費系統皆有其付款機制的特性與適用的環境,透過網路等媒介提供使用者便利性,但也帶來安全與效率的議題。銀行在付費系統中扮演產生票據與驗證票據的功能,在處理大量的交易業務時,計算的效率與資料庫比對的效率顯得非常重要,因此,如何提供一個兼具安全與效率的電子付費系統是一個重要的研究課題。本論文提出一個具效率並採用一次性信用卡號的信用卡付費機制,此機制除了可以避免一般使用信用卡電子付費導致卡號洩漏的問題,在執行效率上,於延遲驗證時可以省去批次比對的步驟,大幅節省銀行驗證時的計算負擔。此外,我們也提出一個可以簡易地產生一次性信用卡號方法,可以大輻改善信用卡號驗證之效能。

並列摘要


Along with the blooming development of E-commerce over the Internet, Internet payment systems become increasingly important. Each Internet payment system has its own characteristics in payment mechanism and applied environment. Although these payment systems provide much convenience via network and other media, various security and efficiency issues are to be investigated. Among current payment systems, banks play an important role in generation and verification of payment credentials used in the payment systems. To provide a secure payment service, a lot of computation cost and maintenance overhead is usually required in banks. As more electronic commerce services are provided in the Internet, it is important to improve the performance of the current payment systems, especially the performance of banks in processing a number of payment transactions. In this paper, we propose an efficient credit card payment system based on one-time credit card transaction numbers. Compared with previous approaches, the proposed system achieves better performance in the verification of one-time credit card numbers, especially when delayed verifications are allowed. We further propose a new way to generate one-time credit card numbers. The proposed method significantly improves the performance of credit card number verification.

參考文獻


Neuman, B. C.,Medvinsky, G.(1995).Requirements for Network Payment: The NetCheque Perspective.Proceedings of the 40th IEEE Computer Society International Conference.(Proceedings of the 40th IEEE Computer Society International Conference).
(Freier, A. O., Karlton, P., & Kocher, P. C. (1996). The SSL Protocol, Version 3.0, Internet Draft, draft-ietf-tls-ssl-version3-00.txt.).
SET Secure Electronic Transaction LLC. (2002). SET Secure Electronic Transaction Specification. Web site: http://www.setco.org/.
Skrawczyk, H.(2001).The Order of Encryption and Authentication for Protecting Communications (or: How Secure Is SSL?).Proceedings of the 21st Annual International Cryptology Conference on Advances in Cryptology.(Proceedings of the 21st Annual International Cryptology Conference on Advances in Cryptology).
Asokan, N.,Janson, P. A.,Steiner, M.,Waidner, M.(1997).The State of the Art in Electronic Payment Systems.IEEE Computer.30,28-35.

延伸閱讀