• 论文 •    

基于可信第三方的安全支付认证模型及其应用

吴小强,刘晶,朱世朋,周荣喜,邱菀华   

  1. 1 北京航空航天大学 经济管理学院,北京100083;2 中国工商银行 北京软件研发中心,北京100080
  • 出版日期:2005-05-15 发布日期:2005-05-25

Research on payment authentication model based on trusted third party

WU Xiao-qiang, LIU Jing, ZHU Shi-peng, ZHOU Rong-xi, QIU Wan-hua   

  1. 1.Sch. of Economics & Management, Beihang Univ., Beijing100083, China; 2. Beijing Software R&D Cent., Industrial & Commercial Bank of China, Beijing100080, China
  • Online:2005-05-15 Published:2005-05-25

摘要: 针对3D(3 Domain)安全协议,对电子交易中敏感隐私信息保护不足的缺点进行了改进,引入了支付认证交易码、支付认证校验码和安全工作流,使3D安全协议中的3个域能在保护敏感信息隐私的前提下安全交易,并构建了基于可信第三方的B2C安全支付认证模型。该模型给出了结合访问控制策略和可扩展标记语言安全技术的设计实例,表明改进的3D SET协议能保障交易中各参与者彼此间的信息隐私,并能适应更复杂的流程管理,更大程度地降低在线购买的风险,进而提高采用在线支付方式的意愿。

关键词: 可信第三方, 隐私, 支付认证, 工作流, 访问控制策略

Abstract: An improved Three Domain (3D) secure protocol and payment authentication model was proposed to guarantee Business-to-Customer (B2C) transactions based on Trusted Third Party (TTP). Payment Authentication Transaction Value (PATV), Payment Authentication Verification Value (PAVV) and secure workflow were introduced to improve the security of 3D secure protocol. Transactions could be safely performed without disclosure of sensitive privacy information among the members in 3D SET. Furthermore, the application of the model, which was integrated with the improved secure protocol, XML security and secure workflow technology, was presented. It was exemplified that the proposed 3D SET solution was designed to protect privacy information, to reduce perceived risk more, and additionally to adapt to more complicated e-Commerce flows. Hence, the work leads to positive intentions towards adoption of online payment.

Key words: trusted third party, privacy, payment authentication, workflow, access control policy

中图分类号: