Micro Tectnology
Micro Tectnology
Lecture 9 Micropayments I
FALL 2002
Micropayments
Replacement of cash Cheaper (cash very expensive to handle) Electronic moves faster Easier to count, audit, verify Small transactions Beverages Phone calls Tolls, transportation, parking Copying Internet content Lotteries, gambling
20-763 ELECTRONIC PAYMENT SYSTEMS FALL 2002 COPYRIGHT 2002 MICHAEL I. SHAMOS
Micropayments
Transactions have low value, e.g. less than $1.00 Must process the transaction at low cost Technological savings: Dont verify every transaction Use symmetric encryption Float-preserving methods Prepayment Grouping
Aggregate purchases (to amortize fixed costs) Provide float to processor Partial anonymity (individual purchases disguised)
FALL 2002
Micropayments
Prepaid cards Issued by non-banks Represent call on future service Not money since usable only with one seller Electronic purse Issued by bank Holds representation of real money In form of a card (for face-to-face or Internet use) In virtual form (computer file for Internet use) The two forms are converging, e.g. wireless
FALL 2002
FALL 2002
GeldKarte
Smart card system Issued by Zentraler Kreditausschu (Germany) Card contains counters representing money value
Max balance 400 DEM = $188
End-of-day: merchant uploads transactions Money credited to merchant account Bank fee: 0.3%, minimum $0.01
20-763 ELECTRONIC PAYMENT SYSTEMS FALL 2002 COPYRIGHT 2002 MICHAEL I. SHAMOS
Loading GeldKarte
LOADING TERMINAL (ATM)
2. AUTHORIZATION REQUEST 1. LOAD REQUEST + PIN
8. VALUE TRANSFER
5. AUTHORIZATION
7. SAM EXCHANGE
4. AUTHORIZATION
6. UPDATE ACCOUNTS
AUTHORIZATION SERVER
ACCOUNT DATABASE
SOURCE: SHERIF
FALL 2002
GeldKarte Payment
Customer inserts GeldKarte in slot (at merchant terminal or PCMCIA card) Merchant authenticates customer card OFFLINE Customer authenticates merchant card (NO THIRD PARTY) Transfer purchase amount Generate electronic receipts (Later) Merchant presents receipt to issuing bank to obtain credit to merchant account No purse-to-purse transactions
20-763 ELECTRONIC PAYMENT SYSTEMS FALL 2002 COPYRIGHT 2002 MICHAEL I. SHAMOS
FALL 2002
FALL 2002
GeldKarte Clearance
Uses a shadow account (Brsenverechnungskonto) to track the contents of the card
When card is loaded, shadow account is credited When money is spent, shadow account is debited online transactions immediately offline transactions later
If card is lost or damaged, money can be replaced Problem: every transaction is recorded, no anonymity Solution: Weisse Karte. Bought for cash, not connected to any bank account
FALL 2002
GeldKarte Security
DES (customer), triple DES (merchant) (cipher block chaining or cipher feedback mode) 128-bit hashes Each card has unique ID, unique symmetric key, PIN stored in secret zone and in bank Unique transaction numbers New SECCOS, Secure Card Operating System, allows PKI and digital signatures
FALL 2002
Wireless potential
20-763 ELECTRONIC PAYMENT SYSTEMS FALL 2002 COPYRIGHT 2002 MICHAEL I. SHAMOS
QIANFLEX (CHINA)
AUSTRIAN QUICK
PRISMERA
DANMNT
FALL 2002
Readers
CASHMOUSE
FALL 2002
Q&A
20-763 ELECTRONIC PAYMENT SYSTEMS FALL 2002 COPYRIGHT 2002 MICHAEL I. SHAMOS