Merx: Secure and Privacy Preserving Delegated Payments

  • Authors:
  • Christopher Soghoian;Imad Aad

  • Affiliations:
  • Berkman Center for Internet and Society, Harvard University, USA;DOCOMO Euro-Labs, Germany

  • Venue:
  • Trust '09 Proceedings of the 2nd International Conference on Trusted Computing
  • Year:
  • 2009

Quantified Score

Hi-index 0.01

Visualization

Abstract

In this paper we present Merx, a secure payment system that enables a user to delegate a transaction to a third party while protecting the user's privacy from a variety of threats. We assume that the user does not trust the delegated person nor the merchant and wishes to minimize the information transmitted to the user's bank. Our system protects the user from fraud perpetrated by the delegated party or by the merchant. The scheme has a number of other applications such as delegating the withdrawal of cash from Automated Teller Machines ATM and allowing companies to restrict an employee's expenses during business trips. Merx is designed to be used with mobile phones and mobile computing devices, especially in situations where end-users do not have access to the Internet. We evaluate the performance of the proposed mechanism and show that it requires negligible overhead and can be gradually deployed as it is able to piggyback on existing payment-network infrastructures.