摘要
针对3D(3 Domain)安全协议,对电子交易中敏感隐私信息保护不足的缺点进行了改进,引入了支付认证交易码、支付认证校验码和安全工作流,使3D安全协议中的3 个域能在保护敏感信息隐私的前提下安全交易,并构建了基于可信第三方的B2C安全支付认证模型。该模型给出了结合访问控制策略和可扩展标记语言安全技术的设计实例,表明改进的3D SET协议能保障交易中各参与者彼此间的信息隐私,并能适应更复杂的流程管理,更大程度地降低在线购买的风险,进而提高采用在线支付方式的意愿。
An improved Three Domain (3D) secure protocol and payment authentication model was proposed to guarantee Business-to-Customer (B2C) transactions based on Trusted Third Party (TTP). Payment Authentication Transaction Value (PATV), Payment Authentication Verification Value (PAVV) and secure workflow were introduced to improve the security of 3D secure protocol. Transactions could be safely performed without disclosure of sensitive privacy information among the members in 3D SET. Furthermore, the application of the model, which was integrated with the improved secure protocol, XML security and secure workflow technology, was presented. It was exemplified that the proposed 3D SET solution was designed to protect privacy information, to reduce perceived risk more, and additionally to adapt to more complicated e-Commerce flows. Hence, the work leads to positive intentions towards adoption of online payment.
出处
《计算机集成制造系统》
EI
CSCD
北大核心
2005年第5期690-695,726,共7页
Computer Integrated Manufacturing Systems
基金
国家自然科学基金资助项目(70372011)
国家十五科技攻关计划专题资助项目(2001BA102A06- 09)~~
关键词
可信第三方
隐私
支付认证
工作流
访问控制策略
trusted third party
privacy
payment authentication
workflow
access control policy