计算机工程与应用 ›› 2013, Vol. 49 ›› Issue (16): 82-85.

• 网络、通信、安全 • 上一篇    下一篇


王  菁,邬书跃,梁  欣   

  1. 湖南涉外经济学院 电气与信息工程学部,长沙 410205
  • 出版日期:2013-08-15 发布日期:2013-08-15

Online security efficient protocol for mobile payment

WANG Jing, WU Shuyue, LIANG Xin   

  1. Department of Information Science and Engineering, Hunan International Economics University, Changsha 410205, China
  • Online:2013-08-15 Published:2013-08-15

摘要: 针对现有移动支付中客户端有限的功耗、处理能力及安全性等问题,提出了一种安全高效的在线移动支付协议。该协议采用客户与银行共享的离线伪随机数作为密钥进行高效认证,能实现高效身份认证及会话密钥协商。客户与商家交易过程中采用共享密钥加密敏感信息,能有效减轻客户端计算开销及实现非否认性。经过效率分析比较及BAN逻辑证明,该协议能以较低的计算及通信量获得较高的安全性,非常适合在移动终端上实现。

关键词: 移动商务, 支付协议, 伪随机数, BAN逻辑

Abstract: In the mobile payment protocols, the client works on wireless devices possibly with limited computation capacities, power and security challenges. In order to satisfy the above properties, a new secure efficient mobile payment protocol is proposed. In this protocol, client and bank can be mutual efficient authenticated and the session key is established due to the shared offline pseudo-random number. The transaction between merchant and client can be processed quickly with the shared key which is the proof of non-repudiation. On the analysis of BAN logic and efficiency, the proposed protocol minimizes the computing and communication requirement of the client that makes it especially suited for mobile devices.

Key words: mobile commerce, payment protocol, pseudo-random number, BAN logic