Lightweight Security Primitives for E-Commerce
نویسندگان
چکیده
Emerging applications in electronic commerce of ten involve very low cost transactions which ex ecute in the context of ongoing extended client server relationships For example consider a web site server which o ers repeated authenticated personalized stock quotes to each of its subscribers clients The value of a single transaction e g de livery of a web page with a customized set of quotes does not warrant the cost of executing a handshake and key distribution protocol Also a client might not always use the same machine during such an extended relationship e g a PC at home a laptop on a trip Typical transport session layer security mechanisms such as SSL and S HTTP either require handshake key distribution for each transaction or do not support client mobility We propose a new security framework for extended relationships between clients and servers based on persistent shared keys We argue that this is a pre ferred model for inexpensive transactions executing within extended relationships Our main contri bution is the design and implementation of a set of lightweight application layer primitives for generating and maintaining persistent shared keys without requiring a client to store any informa tion between transactions and securing a wide range of web transactions e g subscription au thenticated and or private delivery of information receipts with adequate computational cost Our protocols require public key infrastructure only for servers vendors and its usage only once per client upon rst interaction
منابع مشابه
Lightweight 4x4 MDS Matrices for Hardware-Oriented Cryptographic Primitives
Linear diffusion layer is an important part of lightweight block ciphers and hash functions. This paper presents an efficient class of lightweight 4x4 MDS matrices such that the implementation cost of them and their corresponding inverses are equal. The main target of the paper is hardware oriented cryptographic primitives and the implementation cost is measured in terms of the required number ...
متن کاملResource-efficient cryptography for ubiquitous computing
Technological advancements in the semiconductor industry over the last few decades made the mass production of very small-scale computing devices possible. Thanks to the compactness and mobility of these devices, they can be deployed “pervasively”, in other words, everywhere and anywhere – such as in smart homes, logistics, e-commerce, and medical technology. Embedding the small-scale devices i...
متن کاملSecurity Analysis of an Ultra-lightweight RFID Authentication Protocol for M-commerce
Over the last few years, more people perform their social activities on mobile devices, such as mobile payment or mobile wallet. Mobile commerce (m-commerce) refers to manipulating electronic commerce (e-commerce) by using mobile devices and wireless networks. Radio frequency identification (RFID) is a technology which can be employed to complete payment functions on m-commerce. As an RFID subs...
متن کاملEnabling a Lightweight Software Agent Framework for Secure Agent-based Electronic Commerce Applications
Although electronic commerce is a relatively new concept, it has already become a normal aspect of our daily life. The software agent technology is also relatively new. In the area of electronic commerce, software agents could be used for example to search the lowest prices and the best services, to buy goods on behalf of a user, etc. These applications involve a number of security issues that ...
متن کاملLightweight security for mobile commerce transactions
This paper describes a lightweight security mechanism for protecting electronic transactions conducted over the mobile platform. In a typical mobile computing environment, one or more of the transacting parties are based on some wireless handheld devices. Electronic transactions conducted over the mobile platform are gaining popularity and it is widely accepted that mobile computing is a natura...
متن کامل