• DocumentCode
    2110104
  • Title

    A Fundamentally Secure Payment Device Interfaced to Regular PCs

  • Author

    Bouhraoua, Abdelhafid ; Al-Shammari, Metub

  • Author_Institution
    Comput. Eng. Dept., King Fahd Univ. Of Pet. & Miner. (KFUPM), Dhahran
  • fYear
    2008
  • fDate
    17-20 April 2008
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    The present contribution introduces a new way for solving the issue of security for payments over the internet. It particularly addresses the issues related to the PC weaknesses like the combination of key loggers and spyware software. The device uses exclusively symmetric encryption (AES) that ties the device directly to the payment server base at fabrication time. The device is connected to the PC through the USB interface from which it takes its power. The platform architecture is built around three entities: a I/O processor (IOP) responsible for the communication and user interface and a management of keys processor (MKP), responsible for all of the messages processing. Encryption is assured by a dedicated hardware engine for increased performance. The device is made known to the payment server at fabrication time through the assignment of a device ID. Both the server and the device will use secret keys known only to the two parties. This way, the authentication and security are guaranteed at the source. The device ID along with the device and server set of keys are assembled in a data storage packet, scrambled, encrypted by a completely secret device internal key, and stored on a local serial EEPROM. Moreover, the EEPROM setting procedure is a one way procedure where no way of reading back the clear device ID and set of keys is available. The strength of this approach is the fact that the device ID is associated with a set of device keys within the payment server database.
  • Keywords
    EPROM; Internet; cryptography; message passing; system monitoring; EEPROM; I/O processor; Internet; USB interface; data storage packet; fundamentally secure payment device; key loggers; messages processing; regular PC; spyware software; symmetric encryption; Computer architecture; Cryptography; EPROM; Fabrication; Hardware; Internet; Personal communication networks; Universal Serial Bus; User interfaces; Web server; AES; Nonce; Payment Systems; Secure Trusted Device; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Region 5 Conference, 2008 IEEE
  • Conference_Location
    Kansas City, MO
  • Print_ISBN
    978-1-4244-2076-6
  • Electronic_ISBN
    978-1-4244-2077-3
  • Type

    conf

  • DOI
    10.1109/TPSD.2008.4562736
  • Filename
    4562736