{"title":"基于生物特征的椭圆曲线密码电子支付系统三因素相互认证方案","authors":"M. D, S. N","doi":"10.22452/mjcs.sp2020no1.4","DOIUrl":null,"url":null,"abstract":"Electronic payment system plays a vital role in e-commerce and other financial transactions with ever-increasing acceptance of smart device based applications. To ensure secure transactions, various authentication schemes have been proposed in recent times. But existing password and smart card-based traditional e-payment systems have some limitations and also raises security concerns. However, they consume more energy and are not feasible for the e-payment system as it consists of resource constraint devices like mobile devices. Furthermore, it is prone to security issues if the password is guessed or smart card is stolen. Thus to enhance the security and to reduce the computational cost, biometric authentication based payment protocol using elliptic curve cryptography is proposed. Since biometric features are unique and also cannot be stolen or reproduced. The proposed system resists various security attacks like impersonation attack, replay attack, session key agreement, man-in-the-middle attack, and user anonymity. Furthermore, it reduces computational and communication costs when compared to other protocols as it exploits ECC. Thus the proposed authentication protocol is convenient for the electronic payment system. A simulation tool, AVISPA is utilized to verify the security of designed payment protocol and BAN logic for formal security analysis.","PeriodicalId":49894,"journal":{"name":"Malaysian Journal of Computer Science","volume":" ","pages":""},"PeriodicalIF":1.1000,"publicationDate":"2020-11-27","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"BIOMETRIC BASED THREE-FACTOR MUTUAL AUTHENTICATION SCHEME FOR ELECTRONIC PAYMENT SYSTEM USING ELLIPTIC CURVE CRYPTOGRAPHY\",\"authors\":\"M. D, S. N\",\"doi\":\"10.22452/mjcs.sp2020no1.4\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Electronic payment system plays a vital role in e-commerce and other financial transactions with ever-increasing acceptance of smart device based applications. To ensure secure transactions, various authentication schemes have been proposed in recent times. But existing password and smart card-based traditional e-payment systems have some limitations and also raises security concerns. However, they consume more energy and are not feasible for the e-payment system as it consists of resource constraint devices like mobile devices. Furthermore, it is prone to security issues if the password is guessed or smart card is stolen. Thus to enhance the security and to reduce the computational cost, biometric authentication based payment protocol using elliptic curve cryptography is proposed. Since biometric features are unique and also cannot be stolen or reproduced. The proposed system resists various security attacks like impersonation attack, replay attack, session key agreement, man-in-the-middle attack, and user anonymity. Furthermore, it reduces computational and communication costs when compared to other protocols as it exploits ECC. Thus the proposed authentication protocol is convenient for the electronic payment system. A simulation tool, AVISPA is utilized to verify the security of designed payment protocol and BAN logic for formal security analysis.\",\"PeriodicalId\":49894,\"journal\":{\"name\":\"Malaysian Journal of Computer Science\",\"volume\":\" \",\"pages\":\"\"},\"PeriodicalIF\":1.1000,\"publicationDate\":\"2020-11-27\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Malaysian Journal of Computer Science\",\"FirstCategoryId\":\"94\",\"ListUrlMain\":\"https://doi.org/10.22452/mjcs.sp2020no1.4\",\"RegionNum\":4,\"RegionCategory\":\"计算机科学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q4\",\"JCRName\":\"COMPUTER SCIENCE, ARTIFICIAL INTELLIGENCE\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Malaysian Journal of Computer Science","FirstCategoryId":"94","ListUrlMain":"https://doi.org/10.22452/mjcs.sp2020no1.4","RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q4","JCRName":"COMPUTER SCIENCE, ARTIFICIAL INTELLIGENCE","Score":null,"Total":0}
BIOMETRIC BASED THREE-FACTOR MUTUAL AUTHENTICATION SCHEME FOR ELECTRONIC PAYMENT SYSTEM USING ELLIPTIC CURVE CRYPTOGRAPHY
Electronic payment system plays a vital role in e-commerce and other financial transactions with ever-increasing acceptance of smart device based applications. To ensure secure transactions, various authentication schemes have been proposed in recent times. But existing password and smart card-based traditional e-payment systems have some limitations and also raises security concerns. However, they consume more energy and are not feasible for the e-payment system as it consists of resource constraint devices like mobile devices. Furthermore, it is prone to security issues if the password is guessed or smart card is stolen. Thus to enhance the security and to reduce the computational cost, biometric authentication based payment protocol using elliptic curve cryptography is proposed. Since biometric features are unique and also cannot be stolen or reproduced. The proposed system resists various security attacks like impersonation attack, replay attack, session key agreement, man-in-the-middle attack, and user anonymity. Furthermore, it reduces computational and communication costs when compared to other protocols as it exploits ECC. Thus the proposed authentication protocol is convenient for the electronic payment system. A simulation tool, AVISPA is utilized to verify the security of designed payment protocol and BAN logic for formal security analysis.
期刊介绍:
The Malaysian Journal of Computer Science (ISSN 0127-9084) is published four times a year in January, April, July and October by the Faculty of Computer Science and Information Technology, University of Malaya, since 1985. Over the years, the journal has gained popularity and the number of paper submissions has increased steadily. The rigorous reviews from the referees have helped in ensuring that the high standard of the journal is maintained. The objectives are to promote exchange of information and knowledge in research work, new inventions/developments of Computer Science and on the use of Information Technology towards the structuring of an information-rich society and to assist the academic staff from local and foreign universities, business and industrial sectors, government departments and academic institutions on publishing research results and studies in Computer Science and Information Technology through a scholarly publication. The journal is being indexed and abstracted by Clarivate Analytics'' Web of Science and Elsevier''s Scopus