wisemonkeys logo
FeedNotificationProfileManage Forms
FeedNotificationSearchSign in
wisemonkeys logo

Blogs

Security requirements for Safe E-Payments

profile
HARSH KUMAWAT
Aug 28, 2022
1 Like
0 Discussions
83 Reads

Security measures in International and Cross Border financial transactionsSecurity Requirements for Safe E-Payment Systems

The concrete security requirements of electronic payment systems vary, depending on both on their features and the trust assumptions placed on their operation. In general, however, electronic payment systems must exhibit integrity, authorization, confidentiality, availability, and reliability

 

 

 

1. Integrity and authorization 

A payment system with integrity allows no money to be taken from a user without explicit authorization by that user.It may also disallow the receipt of payment without explicit consent, to prevent occurrences of things like unsolicited bribery.Authorization constitutes the most2. Out-band authorizatio.In this approach, the verifying party (typically a bank) notifies the authorizing party (the payer) of a transaction.The authorizing party is required to approve or deny the payment using a secure, out-band channel (such as via surface mail or the phone).This is the current approach for credit cards involving mail orders and telephone orders: Anyone who knows a user's credit card data can initiate transactions, and the legitimate user must check the statement and actively complain about unauthorized transactions. If the user does not complain within a certain time (usually 90 days), the transaction is considered "approved" by default

 

 

2. Password authorization

A transaction protected by a password requires that every message from the authorizing party include a cryptographic check value.The check value is computed using a secret known only to the authorizing and verifying parties.This secret can be a personal identification number, a password, or any form of the shared secret.In addition, the shared secret that is short like a six-digit pin is inherently susceptible to various kinds of attacks.They cannot by themselves provide a high degree of security. They should only be used to control access to a physical token like a smart card (or a wallet) that performs the actual authorization using secure cryptographic mechanisms, such as digital signatures4. Signature authorization.In this type of transaction, the verifying party requires the digital signature of the authorizing party Digital signatures provide nonrepudiation of origin: Only the owner of the secret signing key can "sign" messages (whereas everybody who knows the corresponding public verification key can verify the authenticity of signatures.

 

 

3. Confidential

Some parties involved may wish for the confidentiality of  transactions.Confidentiality in this context means the restriction of the knowledge about various pieces of information related to a transaction: the identity of the payer/payee, purchase content, amount, and so on.Typically, the confidentiality requirement dictates that this information be restricted only to the participants involved.Where anonymity or un-traceability are desired, the requirement may be to limit this knowledge to certain subsets of the participants only, as described later

 

 

4. Availability and reliability 

All parties require the ability to make or receive payments whenever necessary.Payment transactions must be atomic: They occur entirely or not at all, but they never hang in an unknown or inconsistent state. No payer would accept a loss of money (not a significant amount, in any case) due to a network or system crash.Availability and reliability presume that the underlying networking services and all software and hardware components are sufficiently dependable.Recovery from crash failures requires some sort of stable storage at all parties and specific resynchronization protocols.These fault tolerance issues are not discussed here because most payment systems do not address them explicitly.    

.    


Comments ()


Sign in

Read Next

Unlocking Success: Mastering Google Ads Strategies

Blog banner

Lemon and Chilli Pickle (Limbu Mirchi Achar)

Blog banner

How to Manage Employees and Tasks in One System (Without Excel)

Blog banner

How College Events Build Real-world Skills You Can’t Learn From Textbooks

Blog banner

Does School Infrastructure Really Matter For Learning?

Blog banner

MEMORY MANAGEMENT

Blog banner

Developments in Modern Operating Systems

Blog banner

The Chapped Lips and Dry Mouth Trap: The Sneaky Reason Cavities Spike in Winter

Blog banner

Install Ubuntu Easily

Blog banner

The IT Service Lifecycle

Blog banner

1 Dentist in Maroubra, Sydney and her 10 obsessions

Blog banner

Embedded Operating System

Blog banner

OPERATING SYSTEM OBJECTIVES AND FAULT TOLERENCE.

Blog banner

Modern Operating System

Blog banner

Some web vulnerabilities

Blog banner

What is Brute Force Attack? How to defend against it?

Blog banner

The Power of Forensic Watermarking in the Fight Against Content Piracy

Blog banner

Sessions In OS.

Blog banner

MEMORY MANAGEMENT REQUIREMENT

Blog banner

How International Schools Build Global-Minded Students through Curriculum & Activities

Blog banner

Modern Operating System - Khush bagaria

Blog banner

GIS REMOTE SENSING

Blog banner

Virtual memory in Operating System

Blog banner

Deadlock

Blog banner

How Men and Women Process Pain Differently

Blog banner

Understanding Input Based Keylogger Activation Systems: Risks and Mitigation

Blog banner

Processing Crime and Incident Scenes

Blog banner

The Role of Cyber Forensics in Criminology

Blog banner

Sweet and Sour Mango Pickle (Gol Keri)

Blog banner

New Horizon Europe project ‘EvoLand’ sets off to develop new prototype services.

Blog banner

american greatines

Blog banner

Why Oak Tree Hotel Is Arcadia’s Hidden Gem?

Blog banner

Mendeley (management software)

Blog banner

The New Dr. Frankenstein who will perform first full head transplant

Blog banner

AI and cyber Security

Blog banner

Friendship

Blog banner

What is Packet Filtering?

Blog banner

Best Time to Visit Arcadia, Florida & Why Oak Tree Hotel Is Always Ready

Blog banner

ACHIEVEMENTS IN OPERATING SYSTEMS

Blog banner

What Is Experiential Learning and Why Does It Work Better Than Rote Learning?

Blog banner

Dal Bafla Recipe

Blog banner

The Bold Digital Marketing Moves That Made Durex India’s Second-Largest Condom Brand

Blog banner