摘要
大部分现有的移动支付方法都是在完全连接场景下进行的,随着移动电子商务的多样化,现有的移动支付方法已经不能满足移动通信限制场景的要求。为了解决移动通信限制场景下移动支付的安全性问题,在研究3-Dsecure协议的基础上,在商家中心场景(客户和发卡行不能直接连接)下,提出一种新的安全移动支付协议。该协议采用消息恢复签名和对称加密,提供了参与实体之间的相互认证,并实现了匿名性、消息的秘密性和完整性,最后通过改进的Kailar逻辑对协议进行验证,该协议满足可追究性的要求。
Lots of existing mobile payment protocols are based on the scenarios of full connectivity. Because of the diversity of M-commerce the existing mobile payment protocols could not meet the requirements of mobile restrictions communication scenarios. To solve the security issue of the mobile payment in the restrictions communication scenarios, a new security mobile payment protocol in the merchant center scenarios (customers and issuers can not be directly connected) based on studying the 3-D secure protocol is proposed. The protocol uses the message recovery signature scheme and symmetric encryption and provides mutual authentication between the participating entities, and then achieves the anonymity, confidentiality of information and integrity. The new protocol is verified by using the advanced Kailar logic, and results show that the protocol guarantees accountability.
出处
《计算机工程与设计》
CSCD
北大核心
2010年第9期1950-1953,共4页
Computer Engineering and Design
基金
贵州省自然科学基金项目(20052110)
贵州大学引进人才科研基金项目(2008005)
关键词
移动支付
通信限制场景
消息恢复签名
可追究性
匿名性
mobile payment
communication restrictions scenarios
message recovery signature scheme
accountability
anonymity