Electronic Payment Security Technologies
Authentication Your signature here! Digital signatures A unique code applied to an electronically transmitted message that identifies the sender Uses hashing technology so that changing the code will no longer match with the document Your signature here!
Digital Certificates An electronic document that verifies the sender or receiver’s identify Certificate authority Types and classes of digital certificate Site certificates Personal authority certificates Certifying authority certificates Software publisher certificates
Secure Sockets Layer (SSL) A protocol designed to provide a secure connection between the sender and receiver of information Server name of https://
Functioning of SSL Three basic properties of secure channel The channel is private The channel is authenticated The channel is reliable
Establishing an SSL Secure Connection User browses Web Selects payment screen Request sent to server Server returns payment screen Server returns certificate 6. Browser picks one algorithm Browser creates key pair Browser encrypts secret key Browser sends encrypted key to server Server decrypts Two-way encrypted transmissions can occur
Secure Electronic Transaction (SET) A security protocol designed for handling encrypted electronic payments online Specifications include: Confidentiality of information Payment data integrity Authentication of merchants, cardholders, and clearinghouses Interoperability with other protocols Dual Signature
Digital Wallet Software that encrypts payment information and stores it in a file Opponents suggest serious privacy and security issues