Back to Search
Start Over
A secure and efficient authenticated encryption for electronic payment systems using elliptic curve cryptography
- Source :
- Electronic Commerce Research. 16:113-139
- Publication Year :
- 2015
- Publisher :
- Springer Science and Business Media LLC, 2015.
-
Abstract
- The use of e-payment system for electronic trade is on its way to make daily life more easy and convenient. Contrarily, there are a number of security issues to be addressed, user anonymity and fair exchange have become important concerns along with authentication, confidentiality, integrity and non-repudiation. In a number of existing e-payment schemes, the customer pays for the product before acquiring it. Furthermore, many such schemes require very high computation and communication costs. To address such issues recently Yang et al. proposed an authenticated encryption scheme and an e-payment scheme based on their authenticated encryption. They excluded the need of digital signatures for authentication. Further they claimed their schemes to resist replay, man-in-middle, impersonation and identity theft attack while providing confidentiality, authenticity, integrity and privacy protection. However our analysis exposed that Yang et al.'s both authenticated encryption scheme and e-payment system are vulnerable to impersonation attack. An adversary just having knowledge of public parameters can easily masquerade as a legal user. Furthermore, we proposed improved authenticated encryption and e-payment schemes to overcome weaknesses of Yang et al.'s schemes. We prove the security of our schemes using automated tool ProVerif. The improved schemes are more robust and more lightweight than Yang et al.'s schemes which is evident from security and performance analysis.
- Subjects :
- Authenticated encryption
Authentication
Computer science
business.industry
Data_MISCELLANEOUS
Economics, Econometrics and Finance (miscellaneous)
020206 networking & telecommunications
02 engineering and technology
Encryption
computer.software_genre
Computer security
Human-Computer Interaction
0202 electrical engineering, electronic engineering, information engineering
40-bit encryption
56-bit encryption
020201 artificial intelligence & image processing
On-the-fly encryption
Elliptic curve cryptography
business
computer
Computer network
Signcryption
Subjects
Details
- ISSN :
- 15729362 and 13895753
- Volume :
- 16
- Database :
- OpenAIRE
- Journal :
- Electronic Commerce Research
- Accession number :
- edsair.doi...........6885db9817006fcd5d3487835e6f0610
- Full Text :
- https://doi.org/10.1007/s10660-015-9192-5