Writing in a recent issue of the Inderscience publication International Journal of Electronic Security and Digital Forensics Mohammed Assora, James Kadirire and Ayoub Shirvani explain how a disposable credit card number would protect consumers from fraud when shopping online.
Today, e-commerce transactions are performed by sending the customer's credit card details over the Internet between a web browser and the e-commerce site. Despite rudimentary security, there are many points at which the process can be compromised by a fraudster.
The most insecure aspect of the whole process, explains Shirvani and colleagues, is the client authentication step because most e-commerce sites usually only require the customer's credit card details to validate the sale. There is no certification on the customer's side of the bargain. This means that anyone who steals your credit card information could use it to buy goods and services online fraudulently.
Customer certification is not the only problem, the researchers say. Once you have entered your credit card details into a shopping or other e-commerce site, these are usually stored unencrypted in the merchant’s database, which means they could be retrieved by anyone with access to that database, whether or not that is an unscrupulous employee or someone breaking in to the database from outside.The researchers point out that more than a decade has passed since computer security experts instigated the Secure Electronic Transaction
(SET) protocol to try to solve this problem by sending the client's credit card details encrypted. However, the system was very complicated and has not been adopted by e-commerce sites.
Instead, Shirvani and colleagues put forward the idea of a disposable credit card number (DCCN) that could overcome the vast majority of security threats. They describe how DCCNs could be generated "off-line" using a pre-shared secret key between the issuer and the customer and used only once to make an electronic purchase.
The concept is related to the credit voucher and gift certificate systems used by some e-commerce sites but the off-line system means no credit card details need pass across the Internet to create the voucher code. The off-line approach would also side-step any potential security and implementation issues that might be associated with online DCCNs such as Private Payment and SecureClick.
In off-line generation of DCCNs, the customer registers his/her credit card with the card issuer and receives an associated secret key. The customer will then use this secret key in conjunction with a simple calculation device such as a smart card, PDA or mobile phone to generate an encrypted code - known as a hash - that is based on the price of the goods he/she intends to purchase and other details pertinent to the e-commerce site.
The resulting hash is adapted to form the DCCN, and then sent over the Internet instead of the actual credit card details. The shopping site validates the DCCN as any normal credit card without ever seeing or having to store their real credit card details. As a result, the client can shop with no need to worry about confidential data being compromised, the researchers conclude.
The RWI/ISL-Container Throughput Index started off well in 2018
22.02.2018 | RWI – Leibniz-Institut für Wirtschaftsforschung
RWI/ISL-Container Throughput Index ending 2017 on a positive note
24.01.2018 | RWI – Leibniz-Institut für Wirtschaftsforschung
Animal photoreceptors capture light with photopigments. Researchers from the University of Göttingen have now discovered that these photopigments fulfill an...
On 15 March, the AWI research aeroplane Polar 5 will depart for Greenland. Concentrating on the furthest northeast region of the island, an international team...
The world’s second-largest ice shelf was the destination for a Polarstern expedition that ended in Punta Arenas, Chile on 14th March 2018. Oceanographers from...
At the 2018 ILA Berlin Air Show from April 25–29, the Fraunhofer Institute for Laser Technology ILT is showcasing extreme high-speed Laser Material Deposition (EHLA): A video documents how for metal components that are highly loaded, EHLA has already proved itself as an alternative to hard chrome plating, which is now allowed only under special conditions.
When the EU restricted the use of hexavalent chromium compounds to special applications requiring authorization, the move prompted a rethink in the surface...
At the ILA Berlin, hall 4, booth 202, Fraunhofer FHR will present two radar sensors for navigation support of drones. The sensors are valuable components in the implementation of autonomous flying drones: they function as obstacle detectors to prevent collisions. Radar sensors also operate reliably in restricted visibility, e.g. in foggy or dusty conditions. Due to their ability to measure distances with high precision, the radar sensors can also be used as altimeters when other sources of information such as barometers or GPS are not available or cannot operate optimally.
Drones play an increasingly important role in the area of logistics and services. Well-known logistic companies place great hope in these compact, aerial...
16.03.2018 | Event News
13.03.2018 | Event News
08.03.2018 | Event News
16.03.2018 | Earth Sciences
16.03.2018 | Physics and Astronomy
16.03.2018 | Life Sciences