新的移动支付协议及其形式化分析

IMPROVEMENT OF MOBILE PAYMENT PROTOCOL AND ITS FORMAL ANALYSIS

  • 摘要: 针对移动支付协议的认证子协议中未对商家身份认证容易遭到恶意商家的匿名攻击和协议未考虑时限性以至于无法确保交易进行的正确性的问题,提出一种新的移动支付协议。新协议通过对商家身份进行认证和引入了时间戳服务器T,实现了用户和商家的双向认证和时限可追究性。通过SVO逻辑和时限逻辑对新移动支付协议进行形式化分析,新的移动支付协议满足双向认证性和时限可追究性。

     

    Abstract: Aimed at the problems that the authentication subprotocol of mobile payment protocol does not authenticate the merchant’s identity, which is vulnerable to anonymous attacks by malicious merchants, and the protocol does not consider the time limit so that it can’t ensure the correctness of the transaction, a new mobile payment protocol is proposed. The new protocol realized the two-way certification of users and merchants and the accountability of time limit by authenticating the merchant’s identity and introducing the timestamp server T. The new mobile payment protocol was formally analyzed through SVO logic and time limit logic. The new mobile payment protocol meets the two-way certification and limit accountability.

     

/

返回文章
返回