26.10.2012 Views

Internet Security - Dang Thanh Binh's Page

Internet Security - Dang Thanh Binh's Page

Internet Security - Dang Thanh Binh's Page

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

H<br />

MD<br />

D<br />

CRs<br />

K pg<br />

M’s<br />

cert<br />

E K#5 (CRq)<br />

E<br />

Newly generated<br />

digital signature<br />

Merchant<br />

Capture request<br />

(CRq)<br />

SET FOR E-COMMERCE TRANSACTIONS 377<br />

DES<br />

K#5<br />

E K#4 (CT) E<br />

Compare<br />

CRs<br />

K pm : merchant's public key<br />

K sm : merchant's private key<br />

K pg : payment gateway's public key<br />

K sg : payment gateway's private key<br />

K pg<br />

D<br />

E K#6 (CRs)<br />

D<br />

D<br />

K sg<br />

DES<br />

K#6<br />

D<br />

DES<br />

K#5<br />

G’s<br />

cert<br />

CR q<br />

Ksm Gateway digital signature<br />

Payment gateway<br />

Capture response<br />

(CRs)<br />

DES<br />

K#4<br />

Figure 11.9 Payment capture process.<br />

• The merchant verifies the gateway’s digital signature by decrypting it with the<br />

gateway’s public key and comparing the result with a newly generated message<br />

digest of the capture response.<br />

Figure 11.9 shows an overview of payment capture consisting of the merchant’s capture<br />

request and the gateway’s capture response.<br />

D<br />

E<br />

CT<br />

CT<br />

E<br />

H<br />

K pm<br />

DES<br />

K#6<br />

E<br />

K sg<br />

MD<br />

E

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!