18.12.2012 Views

Proceedings

Proceedings

Proceedings

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

ANALYZING E-COMMERCE PROTOCOLS<br />

Carmen TIMOFTE 1<br />

Bucharest Academy of Economic Studies, Romania<br />

ABSTRACT<br />

Many researchers have looked at the problem of verifying e-commerce protocols, but much<br />

work remains to be done. On the final, I present the trends for the utilization of formal<br />

methods for the verification of modern complicated protocols and protocol suites for the real<br />

commercial world.<br />

KEYWORDS: E-commerce, protocols, SET, AADS, 3D Secure, SSL.<br />

INTRODUCTION<br />

Electronic commerce requires protocols of great complexity. To make a purchase over<br />

the Internet, the customer typically submits his credit card number to the merchant,<br />

protected by a protocol such as SSL. However, many potential customers are uneasy<br />

about revealing their credit card number over the Internet. The SET protocol has been<br />

proposed by a consortium of credit card and software companies.<br />

SET aims to protect sensitive card-holder information, to ensure payment integrity<br />

and to authenticate merchants and card-holders.<br />

The paper provides a review of the existing e-commerce protocols, making an<br />

analysis of their most important characteristics. The purpose is to determine the trends<br />

and to present a formal method for verification of these protocols.<br />

1. OVERVIEW OF EXISTING PROTOCOLS<br />

All existing protocols (A & M, 2007) use cryptographic functions like: message<br />

digest (integrity), secret key encryption (privacy), public key, encryption (privacy and<br />

authentication), digital envelopes (integrity and privacy), digital signatures<br />

(authentication), digital certificates (authentication).<br />

E-commerce protocols that were developed and some of them, used, more often or<br />

less often, are:<br />

• SET (Secure Electronic Transaction)- in 1996 it was developed by Visa şi<br />

Mastercard, with the assistence of IBM, Microsoft, Netscape, GTE, SAIC,<br />

Terisa and Verisign;<br />

1<br />

Correspondence address: Carmen TIMOFTE, Economic Informatics Department, Academy of<br />

Economic Studies; email: carmen@ase.ro<br />

~ 488 ~

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!