跳到主要內容

臺灣博碩士論文加值系統

(216.73.217.177) 您好!臺灣時間:2026/08/13 02:40
字體大小: 字級放大   字級縮小   預設字形  
回查詢結果 :::

詳目顯示

我願授權國圖
: 
twitterline
研究生:陳宏岳
研究生(外文):Hung-Yueh Chen
論文名稱:異質行動網路之安全電子付費架構
論文名稱(外文):A Secure Mobile Electronic Payment Architecture for Heterogeneous Wireless Mobile Networks
指導教授:林風林風引用關係
指導教授(外文):Phone Lin
學位類別:碩士
校院名稱:國立臺灣大學
系所名稱:資訊工程學研究所
學門:工程學門
學類:電資工程學類
論文種類:學術論文
論文出版年:2006
畢業學年度:94
語文別:英文
論文頁數:57
中文關鍵詞:雙線性配對身分為基礎密碼系統小額計費行動應用安全性計費
外文關鍵詞:Bilinear PairingIdentity-Based CryptographyMicropaymentMobile ApplicationSecurityBilling
相關次數:
  • 被引用被引用:0
  • 點閱點閱:197
  • 評分評分:
  • 下載下載:0
  • 收藏至我的研究室書目清單書目收藏:1
隨著各種異質無線行動網路廣泛的建置完成,網路業者開始關注於「行動加值服務」的發展,以因應行動商務與電子交易的高度需求。為了吸引更多的行動加值服務使用者,一個具可靠及健全的良好交易模型是不可或缺的。本研究提出並且實作一個架構於異質無線行動網路上的安全行動電子交易平台:“MEP (Mobile Electronic Payment)”。為了能夠適用於低運算能力的行動裝置之上,本MEP平台致力於降低運算及記憶體空間之需求。在安全性方面,本平台應用新興的“身分基礎密碼系統 (ID-based cryptography)”來建立及管理使用者的金鑰,而省去傳統機制需要憑證的負擔,本平台同時滿足交易安全的必要條件:避免超額與重複付費、維持公平性、保障隱私性、以及滿足使用者匿名性。本MEP平台的建置成本相當低廉,並且可以與現有行動業者整合,另外由於本平台實作於網路的應用層,因此可適用於各種不同的底層網路。我們預期所提出的MEP平台可以為未來的行動服務提供一個安全且可行的交易架構。
When the basic functionalities of heterogeneous wireless mobile networks have been in place, network operators are interested in creating value-added mobile applications due to the high demand of electronic trading over the wireless networks or mobile commerce (m-commerce). A good solid secure and robust trading model is needed in order to attract more users (customers) of mobile applications.
This paper proposes and implements a secure trading platform named Mobile Electronic Payment (MEP) for heterogeneous wireless mobile networks, which applies the emerging ID-based cryptography for key agreement and management. Our MEP platform attempts to alleviate the
computational cost, reduce the memory space requirement in mobile devices and meet the requirements for secure trading: avoidance of overspending and double spending, the fairness, the user anonymity, and the privacy. Our design is transparent to the bearer networks and is of low deployment cost. We expect that our MEP provides a viable trading architecture for the future mobile applications.
1 Introduction 13
2 Basics of the ID-Based Cryptography 19
3 The Mobile Electronic Payment (MEP) Platform 23
3.1 The Key Distribution Procedure . . . . . . . . . . . . . . . . . . . . . . . . . 24
3.2 Payment Transaction inMEP . . . . . . . . . . . . . . . . . . . . . . . . . . 26
3.2.1 Withdrawal Phase . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27
3.2.2 Payment Phase . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32
3.2.3 Deposit Phase . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34
4 The Implementation of the MEP Platform 37
5 Features and Overhead Analysis of MEP 43
5.1 Features ofMEP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 43
5.1.1 Avoidance of Overspending and Double Spending . . . . . . . . . . . 43
5.1.2 Fairness . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44
5.1.3 User Anonymity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44
5.1.4 Privacy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 45
5.2 Computational Overhead ofMEP . . . . . . . . . . . . . . . . . . . . . . . . 46
5.2.1 Token Generation and Verification . . . . . . . . . . . . . . . . . . . 46
5.2.2 Message Encryption and Decryption . . . . . . . . . . . . . . . . . . 47
5.2.3 Symmetric-Key Update . . . . . . . . . . . . . . . . . . . . . . . . . . 47
6 Conclusion 49
[1] Download Java 2 Platform, Standard Edition 5.0; [Online] Available:
http://java.sun.com/j2se/1.5.0/download.jsp.
[2] Java ME Downloads; [Online] Available: http://java.sun.com/javame/downloads/ index.
html.
[3] Java Platform, Micro Edition (Java ME); [Online] Available:
http://java.sun.com/javame/index.jsp.
[4] Java Platform, Standard Edition (Java SE); [Online] Available:
http://java.sun.com/javase/index.jsp.
[5] Mobile Solutions, Mobile Applications, and Handheld Devices from Microsoft Windows
Mobile; [Online] Available: http://www.microsoft.com/windowsmobile/default.mspx.
[6] MSDN: Registering an Application to a URL Protocol; [Online] Available:
http://msdn.microsoft.com/library/default.asp?url=/workshop/networking/pluggable/
overview/appendix a.asp.
[7] The Legion of the Bouncy Castle; [Online] Available:
http://www.bouncycastle.org/latest releases.html.
[8] VideoLAN-The streaming solution; [Online] Available:
http://www.videolan.org/streaming/.
[9] 3GPP. 3rd Generation Partnership Project; Charging Architecture and Principles (Release
6). Technical Report 3GPP TS 32.240 V6.3.0, September 2005.
[10] 3GPP. 3rd Generation Partnership Project; Diameter Charging Applications (Release
7). Technical Report 3GPP TS 32.299 V7.1.0, March 2006.
[11] 3GPP. 3rd Generation Partnership Project; IP Multimedia Subsystem (IMS); Stage 2
(Release 7). Technical Report 3GPP TS 23.228 V7.3.0, March 2006.
[12] Anderson, M. M. Financial Service Markup Language (FSML) Version 1.17.1. Technical
Report Financial Services Technology Consortium, October 1998.
[13] Asokan, N., Janson, P. A., Steiner, M., and Waidner, M. The State of the Art in
Electronic Payment Systems. IEEE Computer, 30(9):28–35, September 1997.
[14] Barreto, P., Kim, H., Bynn, B., and Scott, M. Efficient Algorithms for Pairing-Based
Cryptosystems. Proceedings of 22nd Annual International Cryptology Conference Santa
Barbara, 2442:354–368, Springer-Verlag 2002.
[15] Barreto, P. S. L. M., Ben, L., and Michael, S. Efficient Implementation of Pairing-Based
Cryptosystems. Journal of Cryptology, 17(4):321–334, 2004.
[16] Bellare, M., Garay, J., Hauser, R., Herzberg, A., Krawczyk, H., Steiner, M., Tsudik,
G., Herreweghen, E., and Waidner, M. Design, Implementation and Deployment of a
Secure Account-Based Electronic Payment System. IEEE Journal on Selected Areas in
Communications, 18:611–627, April 2000.
[17] Boly, J. P., Bosselaers, A., Cramer, R., Michelsen, R., Mjolsnes, S. F., Muller, F.,
Pedersen, T. P., Pfitzmann, B., Rooij, P. de, Schoenmakers, B., Schunter, M., Vallee, L.,
and Waidner, M. The ESPRIT Project CAFE-High Security Digital Payment Systems.
Proceedings of ESORICS, pages 217–230, 1994.
[18] Boneh, D. and Franklin, M. Identity-Based Encryption from Weil Pairing. Proceedings
of Crypto 2001, 2139:213–229, 2001.
[19] Camenisch, J., Maurer, U., and Stadler, M. Digital Payment Systems with Passive
Anonymity-Revoking Trustees. Proceedings of ESORICS, pages 33–43, 1996.
[20] Edoh, K. D. Elliptic Curve Cryptography: Java Implementation. Proceedings of the
1st Annual Conference on Information Security Curriculum Development, pages 88–93,
2004.
[21] Fancher, C. H. In Your Pocket: Smartcards. IEEE Spectrum, 34:47–53, February 1997.
[22] Ferreira, L. and Dahab, R. A Scheme for Analyzing Electronic Payment Systems.
Proceedings of ACSAC, pages 137–146, 1998.
[23] Grimaldi, R. Discrete and Combinational Mathematics, Fifth Edition. Addison-Wesley,
1999.
[24] Handley, M., Schulzrinne, H., and Schooler, E. SIP: Session Initiation Protocol. Technical
Report RFC 2543, July 1997.
[25] Heikki, K., Ari, A., Lauri, L., Siamak, N., and Valtteri, N. UMTS Networks-
Architecture, Mobility & Services. John Wiley & Sons, Inc., 2002.
[26] Herzberg, A. and Yochai, H. Mini-Pay: Charging Per Click on the Web. Proceedings
of the Sixth International World Wide Web Conference, Santa Clara, California, pages
301–307, April 1997.
[27] Hess, F. Efficient Identity Based Signature Schemes Based on Pairings. Proceeding
of Selected Areas in Cryptography: 9th Annual International Workshop, 2595:310–324,
August 2002.
[28] Hwu, J.-S., Chen, R.-J., and Lin, Y.-B. An Identity-based Cryptosystem for End-to-end
Mobile Security. IEEE Transactions on Wireless Communications, 2006. Accepted for
publication.
[29] IEEE. IEEE Std 802.11-1997 Information Technology-Telecommunications and Information
Exchange between Systems-Local and Metropolitan Area Networks-Specific
Requirements-Part 11: Wireless Lan Medium Access Control (MAC) and Physical Layer
(PHY) Specifications. Technical Report IEEE Std 802.11-1997, 1997.
[30] IEEE. IEEE Standard for Local and Metropolitan Area Networks-Part 16: Air Interface
for Fixed Broadband Wireless Access Systems. Technical Report IEEE Std 802.16-2004,
2004.
[31] Jonsson, J. and Kaliski, B. Public-Key Cryptography Standards (PKCS) #1: RSA
Cryptography Specifications Version 2.1. Technical Report RFC 3447, 2003.
[32] Lai, Y.-C., Lin, P., and Huang, Y.-T. Design and Implementation of a Wireless Internet
Remote Access Platform. Journal of Wireless Communications and Mobile Computing,
6(4):413–429, January 2006.
[33] Lee, Z.-Y., Yu, H.-C., and Ku, P.-J. An Analysis and Comparison of Different Types
of Electronic Payment Systems. Proceedings of Portland International Conference on
Management of Engineering and Technology, 2001. PICMET’01, 2:38–45, 2001.
[34] Lin, P., Chang, H.-M., Fang, Y., and Cheng, S.-M. HISNs: Distributed Gateways
for Application-Level Integration of Heterogenous Wireless Networks. ACM Wireless
Networks, 2006. Accepted for publication.
[35] Lin, Y.-B. and Chlamtac, I. Wireless and Mobile Network Architectures. John Wiley &
Sons, Inc., 2001.
[36] Low, S., and Maxemchuk, N. Anonymous Credit Cards. Proceedings of 2nd ACM
Conference on Computer and Communications Security, pages 108–117, 1994.
[37] Mastercard and Visa. SET Secure Electronic Transactions Protocol, version 1.0 edition,
Book One: Business Specifications, Book Two: Technical Specification, Book Three:
Formal Protocol Definition. May 1997.
[38] Medvinsky, F. and Neuman, B. NetCash: A Design for Practical Electronic Currency
on the Internet. Proceedings of the First ACM Conference on Computer and Communications
Security, pages 102–106, 1993.
[39] Menezes, A., Oorschot, P. V., and Vanstone, S. Handbook of Applied Cryptography;
[Online] Available: http://citeseer.ist.psu.edu/428600.html, 1999.
[40] Rivest, R. L. and Shamir, A. PayWord and MicroMint: Two Simple Micropayment
Schemes. IEEE Transactions on Vehicular Technology, 52(1):132–141, 2003.
[41] Shamir, A. Identity-Based Cryptosystems and Signature Schemes. Proceedings of
CRYPTO 84 on Advances in cryptology, pages 47–53, 1985.
[42] Stallings, W. Cryptography and Network Security: Principles and Practice, Second
Edition. Prentice-Hall, 1999.
[43] Wang, H. and Guo, H. Fair Payment Protocols for E-Commerce. Proceedings of the
22th Annual Symposium on Principles of Distributed Computing, pages 227–245, 2004.
[44] Yang, Z., Lang, W., and Tan, Y. A New Fair Micropayment System Based on Hash
Chain. Proceedings of IEEE International Conference on e-Technology, e-Commerce
and e-Service. EEE’04, pages 139–145, 2004.
[45] Yen, S.-M. PayFair: A Prepaid Internet Micropayment Scheme Ensuring Customer Fairness.
Proceedings of IEE Computers and Digital Techniques, 148(6):207–213, November
2001.
[46] Zhang, Y. and Fang, Y. A Secure Authentication and Billing Architecture for Wireless
Mesh Networks. ACM Wireless Networks, 2006. Accepted for publication.
[47] Zhang, Y., and Fang, Y. ARSA: An Attack-resilient Security Architecture for Multi-hop
Wireless Mesh Networks. IEEE Journal on Selected Areas in Communications, 2006.
Accepted for publication.
[48] Zhang, Y., Liu, W., Lou W., and Fang, Y. Anonymous Handshakes in Mobile Ad
Hoc Networks. IEEE Transactions on Wireless Communications, 2006. Accepted for
publication.
[49] Zhang Y., Liu W., Lou W., and Fang Y. Location-based Security Mechanisms in Wireless
Sensor Networks. IEEE Journal on Selected Areas in Communications, 24(2):247–
260, February 2006.
[50] Zhang, Y., Liu W., Lou W., and Fang, Y. Securing Mobile Ad Hoc Networks with
Certificateless Public Keys. IEEE Transactions on Dependable and Secure Computing,
Accepted for publication.
QRCODE
 
 
 
 
 
                                                                                                                                                                                                                                                                                                                                                                                                               
第一頁 上一頁 下一頁 最後一頁 top