SET Secure Electronic Transaction Setting The Stage For

  • Slides: 21
Download presentation
SET – Secure Electronic Transaction Setting The Stage For Safe Internet Shopping -Jignesh Shah-Riyaz

SET – Secure Electronic Transaction Setting The Stage For Safe Internet Shopping -Jignesh Shah-Riyaz Malbari-

History/Background: -Internet shopping didn’t quite pick up as consumers considered financial transactions over the

History/Background: -Internet shopping didn’t quite pick up as consumers considered financial transactions over the internet, unsafe -Lacks the on one transaction feeling. -Visa & MC came up with the idea what we call as SET.

Advantages: -Privacy: Uses 1024 bit public key cryptography which renders the intercepted message unreadable

Advantages: -Privacy: Uses 1024 bit public key cryptography which renders the intercepted message unreadable ! -Integrity: Hashing & signing ensures message sent is unaltered. -Authentication: Uses digital certificates to ensure the parties are really who they claim to be.

How SET Works: Components: Cardholder Merchant Acquirer Gateway Certification Authority

How SET Works: Components: Cardholder Merchant Acquirer Gateway Certification Authority

1. Cardholder initializes purchase 2. Merchant verifies funds 3. Acquirer purchase & 6. Makesauthorizes

1. Cardholder initializes purchase 2. Merchant verifies funds 3. Acquirer purchase & 6. Makesauthorizes transfers & 4. Order is payment to Verifies merchant’s certificate 5. provides Requests payment merchant confirmed Merchant’s Bank Cardholder’s Bank

How safe is SET? -Uses 1024–bit cipher keys, making it one of the strongest

How safe is SET? -Uses 1024–bit cipher keys, making it one of the strongest encryption applications. -If we use 100 computers each processing 10 MIPS, it would take 2. 8 x 10 11 years to break just ONE encrypted message !!!! Source: http: //www. rsa. com/set/html/howstrong. html

SET versus SSL -SET was developed specifically for payment transaction. SSL simply encrypts the

SET versus SSL -SET was developed specifically for payment transaction. SSL simply encrypts the communication channel between cardholder & merchant website and its not backed by any financial institution. - Compare 128 -bit encryption with that to SET !

SET versus SSL: -SET also authenticates each participant as its backed by CA &

SET versus SSL: -SET also authenticates each participant as its backed by CA & financial institutions. -SET provides security throughout the entire transaction process. SSL provides security only between cardholder and merchant.

Concept of Dual Signature : Alice Bob Bank

Concept of Dual Signature : Alice Bob Bank

Certificate Issuance: Electronic representation of payment card/brand Must be approved by the Acquirer gateway

Certificate Issuance: Electronic representation of payment card/brand Must be approved by the Acquirer gateway

Payment Processing : • Cardholder registeration • Merchant registeration • Purchase request • Payment

Payment Processing : • Cardholder registeration • Merchant registeration • Purchase request • Payment authorisation • Payment capture

Drawbacks: ¨ Slow ¨ Expensive ¨ Not portable

Drawbacks: ¨ Slow ¨ Expensive ¨ Not portable

References: ¨ http: //www. setco. org ¨ http: //www. wolrath. com/set. html ¨ http:

References: ¨ http: //www. setco. org ¨ http: //www. wolrath. com/set. html ¨ http: //www. Master. Card. com

THANK YOU !!!

THANK YOU !!!