Secure Transaction Protocol for CEPS Compliant EPS in Limited Connectivity Environment

  • Authors:
  • Satish Devane;Deepak Phatak

  • Affiliations:
  • Ramrao Adik Institute of Technology, Navi Mumbai, 400706 India;Indian Institute of Technology Bombay Powai, Mumbai, India 400076

  • Venue:
  • EC-Web 2009 Proceedings of the 10th International Conference on E-Commerce and Web Technologies
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Common Electronic Purse Specification (CEPS) used by European countries, elaborately defines the transaction between customer's CEP card and merchant's point of sales (POS) terminal. However it merely defines the specification to transfer the transactions between the Merchant and Merchant Acquirer (MA). This paper proposes a novel approach by introducing an entity, mobile merchant acquirer (MMA) which is a trusted agent of MA and principally works on man in middle concept, but facilitates remote two fold mutual authentication and secure transaction transfer between Merchant and MA through MMA. This approach removes the bottle-neck of connectivity issues between Merchant and MA in limited connectivity environment. The proposed protocol ensures the confidentiality, integrity and money atomicity of transaction batch. The proposed protocol has been verified for correctness by Spin, a model checker and security properties of the protocol have been verified by avispa.