计算机科学
计算机安全
付款
智能卡
协议(科学)
钥匙(锁)
互联网隐私
数据库事务
数据库
万维网
医学
替代医学
病理
作者
Sergiu Bursuc,Ross Horne,Sjouke Mauw,Semen Yurkov
标识
DOI:10.1145/3576915.3623109
摘要
The most prevalent smart card-based payment method, EMV, currently offers no privacy to its users. Transaction details and the card number are sent in cleartext, enabling the profiling and tracking of cardholders. Since public awareness of privacy issues is growing and legislation, such as GDPR, is emerging, we believe it is necessary to investigate the possibility of making payments anonymous and unlikable without compromising essential security guarantees and functional properties of EMV. This paper draws attention to trade-offs between functional and privacy requirements in the design of such a protocol. We present the UTX protocol - an enhanced payment protocol satisfying such requirements, and we formally certify key security and privacy properties using techniques based on the applied π-calculus.
科研通智能强力驱动
Strongly Powered by AbleSci AI