A limited-used key generation scheme for internet transactions

  • Authors:
  • Supakorn Kungpisdan;Phu Dung Le;Bala Srinivasan

  • Affiliations:
  • School of Computer Science and Software Engineering, Monash University, Caulfield East, Victoria, Australia;School of Network Computing, Monash University, Frankston, Victoria, Australia;School of Computer Science and Software Engineering, Monash University, Caulfield East, Victoria, Australia

  • Venue:
  • WISA'04 Proceedings of the 5th international conference on Information Security Applications
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

Traditionally, the security of symmetric-key based systems heavily relies on the security of shared keys. In this paper, we present a new session key generation technique for internet transactions that eliminates the need of storing long-term shared key which makes the system insecure against key compromise during transactions. The generation of each set of session keys is based on randomly chosen preference keys. The higher number the transactions have been performed, the less chance the system is being compromised. We show that the proposed technique is secure against various kinds of attacks. Finally, the proposed technique can be applied to any kind of internet applications that deploy shared secrets. We demonstrate the practical usefulness of our technique by applying it to credit-card payment systems. The results show that our technique enhance their security considerably.