首页> 外文会议>International conference on human-computer interaction >Frictionless Web Payments with Cryptographic Cardholder Authentication
【24h】

Frictionless Web Payments with Cryptographic Cardholder Authentication

机译:具有加密持卡人身份验证的无摩擦Web支付

获取原文

摘要

The 3-D Secure protocol, introduced 20years ago, aims at reducing online credit card fraud by authenticating the cardholder. Version 2 of the protocol, not yet deployed, addresses usability problems that have hindered the deployment of version 1 by introducing a fric-tionless flow for low risk transactions. But the frictionless flow does not authenticate the cardholder. Instead, it requires the merchant to send information to the issuer through a back channel, potentially violating the cardholder's privacy. The paper analyzes the usability, privacy and security provided by 3-D Secure 2 and proposes an alternative protocol, simpler and less expensive to implement, where the cardholder is authenticated with a cryptographic credential stored in the cardholder's browser with zero friction. The scheme can take advantage of a native bank app in the cardholder's device to further authenticate the cardholder by fingerprint scanning or face recognition as made available by the device, and can be used for credit card purchases made on the merchant's web site or on a merchant app.
机译:20年前推出的3-D安全协议旨在通过对持卡人进行身份验证来减少在线信用卡欺诈。该协议的版本2(尚未部署)通过为低风险交易引入无摩擦的流程来解决阻碍版本1部署的可用性问题。但是,顺畅的流程无法验证持卡人的身份。取而代之的是,它要求商户通过反向渠道将信息发送给发行人,这有可能侵犯持卡人的隐私。本文分析了3-D Secure 2提供的可用性,隐私和安全性,并提出了一种替代协议,该协议实施起来更简单且成本更低,其中持卡人使用存储在持卡人浏览器中的加密凭据进行了身份验证,且摩擦零。该方案可以利用持卡人设备中的本机银行应用程序进一步通过设备提供的指纹扫描或面部识别来对持卡人进行身份验证,并且可以用于在商家网站或商家上进行的信用卡购买应用程序。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号