DocumentCode :
2110104
Title :
A Fundamentally Secure Payment Device Interfaced to Regular PCs
Author :
Bouhraoua, Abdelhafid ; Al-Shammari, Metub
Author_Institution :
Comput. Eng. Dept., King Fahd Univ. Of Pet. & Miner. (KFUPM), Dhahran
fYear :
2008
fDate :
17-20 April 2008
Firstpage :
1
Lastpage :
6
Abstract :
The present contribution introduces a new way for solving the issue of security for payments over the internet. It particularly addresses the issues related to the PC weaknesses like the combination of key loggers and spyware software. The device uses exclusively symmetric encryption (AES) that ties the device directly to the payment server base at fabrication time. The device is connected to the PC through the USB interface from which it takes its power. The platform architecture is built around three entities: a I/O processor (IOP) responsible for the communication and user interface and a management of keys processor (MKP), responsible for all of the messages processing. Encryption is assured by a dedicated hardware engine for increased performance. The device is made known to the payment server at fabrication time through the assignment of a device ID. Both the server and the device will use secret keys known only to the two parties. This way, the authentication and security are guaranteed at the source. The device ID along with the device and server set of keys are assembled in a data storage packet, scrambled, encrypted by a completely secret device internal key, and stored on a local serial EEPROM. Moreover, the EEPROM setting procedure is a one way procedure where no way of reading back the clear device ID and set of keys is available. The strength of this approach is the fact that the device ID is associated with a set of device keys within the payment server database.
Keywords :
EPROM; Internet; cryptography; message passing; system monitoring; EEPROM; I/O processor; Internet; USB interface; data storage packet; fundamentally secure payment device; key loggers; messages processing; regular PC; spyware software; symmetric encryption; Computer architecture; Cryptography; EPROM; Fabrication; Hardware; Internet; Personal communication networks; Universal Serial Bus; User interfaces; Web server; AES; Nonce; Payment Systems; Secure Trusted Device; Security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Region 5 Conference, 2008 IEEE
Conference_Location :
Kansas City, MO
Print_ISBN :
978-1-4244-2076-6
Electronic_ISBN :
978-1-4244-2077-3
Type :
conf
DOI :
10.1109/TPSD.2008.4562736
Filename :
4562736
Link To Document :
بازگشت