A secure and efficient authenticated encryption for electronic payment systems using elliptic curve cryptography
Shehzad Ashraf Chaudhry (),
Mohammad Sabzinejad Farash (),
Husnain Naqvi () and
Muhammad Sher ()
Additional contact information
Shehzad Ashraf Chaudhry: International Islamic University
Mohammad Sabzinejad Farash: Kharazmi University
Husnain Naqvi: International Islamic University
Muhammad Sher: International Islamic University
Electronic Commerce Research, 2016, vol. 16, issue 1, No 4, 113-139
Abstract:
Abstract The use of e-payment system for electronic trade is on its way to make daily life more easy and convenient. Contrarily, there are a number of security issues to be addressed, user anonymity and fair exchange have become important concerns along with authentication, confidentiality, integrity and non-repudiation. In a number of existing e-payment schemes, the customer pays for the product before acquiring it. Furthermore, many such schemes require very high computation and communication costs. To address such issues recently Yang et al. proposed an authenticated encryption scheme and an e-payment scheme based on their authenticated encryption. They excluded the need of digital signatures for authentication. Further they claimed their schemes to resist replay, man-in-middle, impersonation and identity theft attack while providing confidentiality, authenticity, integrity and privacy protection. However our analysis exposed that Yang et al.’s both authenticated encryption scheme and e-payment system are vulnerable to impersonation attack. An adversary just having knowledge of public parameters can easily masquerade as a legal user. Furthermore, we proposed improved authenticated encryption and e-payment schemes to overcome weaknesses of Yang et al.’s schemes. We prove the security of our schemes using automated tool ProVerif. The improved schemes are more robust and more lightweight than Yang et al.’s schemes which is evident from security and performance analysis.
Keywords: Authenticated encryption; E-payment system; Elliptic curve cryptography; Digital signature; Signcryption; ProVerif (search for similar items in EconPapers)
Date: 2016
References: View references in EconPapers View complete reference list from CitEc
Citations: View citations in EconPapers (2)
Downloads: (external link)
http://link.springer.com/10.1007/s10660-015-9192-5 Abstract (text/html)
Access to the full text of the articles in this series is restricted.
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:spr:elcore:v:16:y:2016:i:1:d:10.1007_s10660-015-9192-5
Ordering information: This journal article can be ordered from
http://www.springer.com/journal/10660
DOI: 10.1007/s10660-015-9192-5
Access Statistics for this article
Electronic Commerce Research is currently edited by James Westland
More articles in Electronic Commerce Research from Springer
Bibliographic data for series maintained by Sonal Shukla () and Springer Nature Abstracting and Indexing ().