| Privacy-preserving management of transactions' receipts for mobile environments |
| Full text |
Pdf
(688 KB)
|
| Source
|
IDtrust; Vol. 373
archive
Proceedings of the 8th Symposium on Identity and Trust on the Internet
table of contents
Gaithersburg, Maryland
SESSION: Applied cryptography
table of contents
Pages 73-84
Year of Publication: 2009
ISBN:978-1-60558-474-4
|
|
Authors
|
|
Federica Paci
|
Purdue University, West Lafayette, Indiana
|
|
Ning Shang
|
Purdue University, West Lafayette, Indiana
|
|
Sam Kerr
|
Purdue University, West Lafayette, Indiana
|
|
Kevin Steuer, Jr
|
Purdue University, West Lafayette, Indiana
|
|
Jungha Woo
|
Purdue University, West Lafayette, Indiana
|
|
Elisa Bertino
|
Purdue University, West Lafayette, Indiana
|
|
| Sponsors |
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 38, Downloads (12 Months): 170, Citation Count: 0
|
|
|
ABSTRACT
Users increasingly use their mobile devices for electronic transactions to store related information, such as digital receipts. However, such information can be target of several attacks. There are some security issues related to M-commerce: the loss or theft of mobile devices results in a exposure of transaction information; transaction receipts that are send over WI-FI or 3G networks can be easily intercepted; transaction receipts can also be captured via Bluetooth connections without the user's consent; and mobile viruses, worms and Trojan horses can access the transaction information stored on mobile devices if this information is not protected by passwords or PIN numbers. Therefore, assuring privacy and security of transactions' information, as well as of any sensitive information stored on mobile devices is crucial. In this paper, we propose a privacy-preserving approach to manage electronic transaction receipts on mobile devices. The approach is based on the notion of transaction receipts issued by service providers upon a successful transaction and combines Pedersen commitment and Zero Knowledge Proof of Knowledge (ZKPK) techniques and Oblivious Commitment-Based Envelope (OCBE) protocols. We have developed a version of such protocol for Near Field Communication (NFC) enabled cellular phones.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
Jean-Paul Boly , Antoon Bosselaers , Ronald Cramer , Rolf Michelsen , Stig Fr. Mjølsnes , Frank Muller , Torben P. Pedersen , Birgit Pfitzmann , Peter de Rooij , Berry Schoenmakers , Matthias Schunter , Luc Vallée , Michael Waidner, The ESPRIT Project CAFE - High Security Digital Payment Systems, Proceedings of the Third European Symposium on Research in Computer Security, p.217-230, November 07-09, 1994
|
| |
2
|
Bouncy Castle Crypto APIs. http://www.bouncycastle.org/.
|
| |
3
|
Nokia Forum. Nokia 6131 NFC Technical Description. http://www.forum.nokia.com.
|
| |
4
|
Help for lost and stolen phones. http://news.bbc.co.uk/1/hi/technology/4033461.stm.
|
| |
5
|
|
| |
6
|
|
| |
7
|
Met initiative. http://www.mobiletransaction.org.
|
| |
8
|
|
| |
9
|
Near Field Communication Forum. http://www.nfc-forum.org.
|
| |
10
|
|
| |
11
|
SET- Secure Electronic Transaction specification book 1: Business description, 1997. 1992. Springer-Verlag.
|
| |
12
|
|
 |
13
|
|
| |
14
|
TechRepublic. Identify and reduce mobile device security risks. http://articles.techrepublic.com.com/5100-22_11-5274902.html.
|
| |
15
|
J. Veijalainen, V. Y. Terziyan, and H. Tirri. Transaction management for m-commerce at a mobile terminal. Electronic Commerce Research and Applications, 5(3):229--245, 2006.
|
|