首页> 外文会议>Financial cryptography and data security >Verified by Visa and MasterCard SecureCode: Or, How Not to Design Authentication (Short Paper)
【24h】

Verified by Visa and MasterCard SecureCode: Or, How Not to Design Authentication (Short Paper)

机译:通过Visa和MasterCard SecureCode验证:或者,如何不设计身份验证(简短论文)

获取原文
获取原文并翻译 | 示例

摘要

Banks worldwide are starting to authenticate online card transactions using the '3-D Secure' protocol, which is branded as Verified by Visa and MasterCard SecureCode. This has been partly driven by the sharp increase in online fraud that followed the deployment of EMV smart cards for cardholder-present payments in Europe and elsewhere. 3-D Secure has so far escaped academic scrutiny; yet it might be a textbook example of how not to design an authentication protocol. It ignores good design principles and has significant vulnerabilities, some of which are already being exploited. Also, it provides a fascinating lesson in security economics. While other single sign-on schemes such as OpenID, InfoCard and Liberty came up with decent technology they got the economics wrong, and their schemes have not been adopted. 3-D Secure has lousy technology, but got the economics right (at least for banks and merchants); it now boasts hundreds of millions of accounts. We suggest a path towards more robust authentication that is technologically sound and where the economics would work for banks, merchants and customers - given a gentle regulatory nudge.
机译:全球银行开始使用“ 3-D Secure”协议对在线卡交易进行身份验证,该协议的商标为Visa和MasterCard SecureCode验证。这部分是由于在欧洲和其他地方部署了EMV智能卡以用于持卡人在场支付之后,在线欺诈急剧增加。到目前为止,3-D Secure逃脱了学术审查;但它可能是如何不设计身份验证协议的教科书示例。它忽略了良好的设计原则,并具有明显的漏洞,其中一些漏洞已被利用。此外,它在安全经济学方面提供了一个有趣的课程。尽管其他单一登录方案(如OpenID,InfoCard和Liberty)提出了不错的技术,但它们在经济学上是错误的,并且尚未采用它们的方案。 3-D Secure技术糟糕,但经济适用(至少对于银行和商人而言);现在,它拥有数亿个帐户。我们建议采取一种稳健的身份验证方法,该方法在技术上是合理的,并且在轻度的监管推动下,经济适用于银行,商人和客户。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号