Using WPKI for security of web transaction

  • Authors:
  • Mohammed Assora;James Kadirire;Ayoub Shirvani

  • Affiliations:
  • Anglia Ruskin University, Chelmsford, UK;Anglia Ruskin University, Chelmsford, UK;Anglia Ruskin University, Chelmsford, UK

  • Venue:
  • EC-Web'07 Proceedings of the 8th international conference on E-commerce and web technologies
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Today, a web transaction is typically protected by using SSL/TLS. SSL/TLS without compulsion for a client's public key certificate, which is the typical usage, is not able to fulfill the security requirements for web transactions. The main remaining threats for this use are client authentication and non-repudiation. This paper presents a scheme to address SSL/TLS security holes, when it is used for web transaction security. The focus is only on transaction that is carried out by using credit/debit cards. The scheme uses wireless public key infrastructure (WPKI) in the client's mobile phone to generate a digital signature for the client. Thus we obtain client authentication and nonrepudiation. At the same time, no overhead is imposed on the client, there is no need for any change to the actual system when performing the transaction, and no connection, by using the mobile phone, is required to perform the transaction.