Forum for Science, Industry and Business
Sponsored by:     Siemens  n-tv 
Search our Site:

Topic (optional):

 

Home Reports Business and Finance Content

Disposable credit card numbers

next article
22.02.2008

A radical approach to shopping online without risking the security of your banking or credit card details has been devised by researchers at Anglia Ruskin University, in Chelmsford.

 

Writing in a recent issue of the Inderscience publication International Journal of Electronic Security and Digital Forensics Mohammed Assora, James Kadirire and Ayoub Shirvani explain how a disposable credit card number would protect consumers from fraud when shopping online.


Today, e-commerce transactions are performed by sending the customer's credit card details over the Internet between a web browser and the e-commerce site. Despite rudimentary security, there are many points at which the process can be compromised by a fraudster.

The most insecure aspect of the whole process, explains Shirvani and colleagues, is the client authentication step because most e-commerce sites usually only require the customer's credit card details to validate the sale. There is no certification on the customer's side of the bargain. This means that anyone who steals your credit card information could use it to buy goods and services online fraudulently.

Customer certification is not the only problem, the researchers say. Once you have entered your credit card details into a shopping or other e-commerce site, these are usually stored unencrypted in the merchant’s database, which means they could be retrieved by anyone with access to that database, whether or not that is an unscrupulous employee or someone breaking in to the database from outside.

The researchers point out that more than a decade has passed since computer security experts instigated the Secure Electronic Transaction
(SET) protocol to try to solve this problem by sending the client's credit card details encrypted. However, the system was very complicated and has not been adopted by e-commerce sites.

Instead, Shirvani and colleagues put forward the idea of a disposable credit card number (DCCN) that could overcome the vast majority of security threats. They describe how DCCNs could be generated "off-line" using a pre-shared secret key between the issuer and the customer and used only once to make an electronic purchase.

The concept is related to the credit voucher and gift certificate systems used by some e-commerce sites but the off-line system means no credit card details need pass across the Internet to create the voucher code. The off-line approach would also side-step any potential security and implementation issues that might be associated with online DCCNs such as Private Payment and SecureClick.

In off-line generation of DCCNs, the customer registers his/her credit card with the card issuer and receives an associated secret key. The customer will then use this secret key in conjunction with a simple calculation device such as a smart card, PDA or mobile phone to generate an encrypted code - known as a hash - that is based on the price of the goods he/she intends to purchase and other details pertinent to the e-commerce site.

The resulting hash is adapted to form the DCCN, and then sent over the Internet instead of the actual credit card details. The shopping site validates the DCCN as any normal credit card without ever seeing or having to store their real credit card details. As a result, the client can shop with no need to worry about confidential data being compromised, the researchers conclude.

Albert Ang | Source: alphagalileo
Further information: www.inderscience.com/
www.inderscience.com/offer.php?id=16864

next article

More articles from Business and Finance:

nachricht KfW issues its first ever 7 year Euro-Benchmark
25.11.2009 | KfW Bankengruppe

nachricht Five-day delivery no sure cure for postal woes, economist says
25.11.2009 | University of Illinois at Urbana-Champaign

All articles from Business and Finance >>>

B2B Search

Product / Service
Company / Organisation

Latest News

First black holes may have incubated in giant, starlike cocoons

25.11.2009 | Physics and Astronomy

KfW issues its first ever 7 year Euro-Benchmark

25.11.2009 | Business and Finance

Intelligence inside metal components

25.11.2009 | Information Technology

VideoLinks
More VideoLinks >>>

Event News

Multidisciplinary meeting on Urological Cancers aims to benefit cancer patients

20.11.2009 | Event News

'Golden Age' for clinical psychology in Northern Ireland

20.11.2009 | Event News

New Perspectives in Marine Anti-Fouling Research

11.11.2009 | Event News