Presentation is loading. Please wait.

Presentation is loading. Please wait.

Commerce and Financial Transaction Security Over the Internet Dave Crocker Brandenburg +1 408 246 8253www.brandenburg.com.

Similar presentations


Presentation on theme: "Commerce and Financial Transaction Security Over the Internet Dave Crocker Brandenburg +1 408 246 8253www.brandenburg.com."— Presentation transcript:

1 Commerce and Financial Transaction Security Over the Internet Dave Crocker Brandenburg Consultingdcrocker@brandenburg.com +1 408 246 8253www.brandenburg.com Dave Crocker Brandenburg Consultingdcrocker@brandenburg.com +1 408 246 8253www.brandenburg.com

2 © 1998 D. Crocker, Brandenburg Consulting2 What we will cover  Architecture 4 Channel 4 Object  Commerce  Trading  Payment

3 © 1998 D. Crocker, Brandenburg Consulting3 Where to put security? My object Object Secure My object FTP Email Web Secure My object Secure My object Email Channel My object Web Secure Web Server Email Secure MTA

4 © 1998 D. Crocker, Brandenburg Consulting4 Channel security IPSEC IP-level labeling Kerberos (MIT) Third-party service S-KEY/OTP Pairwise login SSL/TSL Client-server link SASL Scheme selection

5 © 1998 D. Crocker, Brandenburg Consulting5 PGP  PGP, Inc.  Qualcomm  Years of use  Significant installed base  Informal CA scheme w/serverS/MIME  RSA DSI  Netscape, Microsoft  No usage history  Sudden large installed base  Formal CA scheme w/ server Object contenders

6 © 1998 D. Crocker, Brandenburg Consulting6 Phases Shopping Searching Negotiating Terms Buying Instrument Paying Exchange

7 © 1998 D. Crocker, Brandenburg Consulting7 Open Trading Protocol  OTP Consortium  Functions 4 Authentication 4 Deposit 4 Purchase 4 Refund 4 Withdrawal 4 Value Exchange

8 © 1998 D. Crocker, Brandenburg Consulting8 Buyer Merchant Issuing Bank Acquiring Bank Clearing House 16+4 M. Rose, FV Risk Management... Payment system model

9 © 1998 D. Crocker, Brandenburg Consulting9 Clearing House Buyer Merchant 16+4 in the clear! Just trust the net... Easy to capture and replay. Scheme “Clear”

10 © 1998 D. Crocker, Brandenburg Consulting10 Clearing House Buyer Merchant 16+4 ID ID 16+4 Still trust the net, until the next statement... Easy to capture and replay. Scheme “ID”

11 © 1998 D. Crocker, Brandenburg Consulting11 Clearing House Buyer 16+4 ID ID Confirm ID Merchant Each transaction confirmed. Requires mildly safe user account. Scheme “ID confirm”

12 © 1998 D. Crocker, Brandenburg Consulting12 Clearing House Buyer Merchant Encrypted 16+4 Same a telephone, but encrypt over Internet. Merchant gets number. Is merchant safe?? Scheme “Secure link”

13 © 1998 D. Crocker, Brandenburg Consulting13 Clearing House Buyer Merchant Encrypted 16+4 Encrypted 16+4 Only banks sees data in clear. Limited points of attack. Scheme “Mediated”


Download ppt "Commerce and Financial Transaction Security Over the Internet Dave Crocker Brandenburg +1 408 246 8253www.brandenburg.com."

Similar presentations


Ads by Google