A Privacy Preserving E-Payment Architecture

نویسندگان

  • Aude Plateaux
  • Vincent Coquet
  • Sylvain Vernois
  • Patrick Lacharme
  • Kumar Murty
  • Christophe Rosenberger
چکیده

This poster proposes a secure e-payment architecture for online shopping protecting users’ privacy. Introduction. Online shopping is becoming more and more interesting for customers because of the ease of use and the large choice of products. A vast amount of sensitive information is transferred during such online payment transactions what involves privacy problems. Current e-payment schemes, such as 3D-Secure or the SET protocol, attempt to ensure the actors’ security, however, the privacy issues are not addressed in the literature. For instance, when the customer wants to purchase an online service, he/she must provide his/her personal bank information: Personal Authentication Number (PAN), Card Verification Value (CVX2) and expiration date. These secret data are then transferred and can be known by all actors while such knowledge is not necessary. Proposition. In the proposed architecture, private information is only disclosed when necessary and hidden from both the service provider SP, and the payment providers. This solution is mainly based on the generation of two documents: an electronic bank cheque associated with certificates and a contract between the SP and the customer. In this architecture, we conserve two of the three 3D-Secure domains: the acquirer domain and the issuer domain. The interoperability domain is replaced by an interbank trusted third party. This interbank system enables communication between banks without disclosing information about the other actors and without adding any additional message. Moreover, this e-payment architecture is fully compliant with the data minimization, data sovereignty and data sensibility principles. More particularly, the payment transaction never discloses any customer’s bank information. Finally, the customer does not need to have particular cryptographic knowledges. Conclusion. While keeping an equivalent level of security, the proposed epayment architecture is more respectful of the actors’ privacy than the ones currently used. This scheme also supports the following properties: the customer’s basket, as well as the SP’s name, are unknown to the customer’s bank. Moreover, the customer does not know the SP’s bank and is unknown to this latter. Finally, the customer’s banking information and the customer’s banks are unknown to the SP.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A centralized privacy-preserving framework for online social networks

There are some critical privacy concerns in the current online social networks (OSNs). Users' information is disclosed to different entities that they were not supposed to access. Furthermore, the notion of friendship is inadequate in OSNs since the degree of social relationships between users dynamically changes over the time. Additionally, users may define similar privacy settings for their f...

متن کامل

A Protocol of Unlinkable Transaction for Preserving Customer Privacy∗

In this paper, we consider the protocol which prevents the service provider from finding out which customer have bought what kind of contents by the unlinkability between the payment and user-profile information. Besides, we do not employ any kind of anonymous payment system causing more computation complexities and overheads to the network, and our approach can be easily applied into the curre...

متن کامل

A Privacy Preserving ECommerce Oriented Identity Management Architecture

A Privacy Preserving ECommerce Oriented Identity Management Architecture

متن کامل

XPACML eXtensible Privacy Access Control Markup Language

Privacy in the digital world is a critical problem which is becoming even more imperious with the growth of the Internet, accompanied by the proliferation of e-services (e.g. ecommerce, e-health). One research track for efficient privacy management is to make use of user’s and service provider’s (SP) privacy policies, and to perform an automatic comparison in between to help any (skilled or uns...

متن کامل

P4R: Privacy-Preserving Pre-Payments with Refunds for Transportation Systems

We propose a new lightweight payment scheme for transit systems called P4R: Privacy-Preserving Pre-Payments with Refunds. In P4R a user deposits money to obtain a bundle of credentials, where each credential allows to make an arbitrary ride. The actual fare of a trip is determined on-the-fly when exiting. Overpayments are refunded where all trip refunds of a user are aggregated in a single toke...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2013