Unit 4 Secure Electronic Transaction
Unit 4 Secure Electronic Transaction
SET
• open encryption & security specification
• to protect Internet credit card transactions
• developed in 1996 by Mastercard, Visa etc Mastercard Visa 1996
• not a payment system
• rather a set of security protocols & formats
• secure communications amongst parties
• trust from use of X.509v3 certificatesX.509v3
• privacy by restricted info to those who need it
• Merchant does not get to know the credit card details of the
cardholder
H POMD E
+
OI H OIMD
Dual Signature
(DS)
Fig 6.31
Please verify the Please verify the
cardholder’s certificate merchant’s certificate
Certificate
Authority
Group
You can act as a CA You can act as a CA
Certificate Certificate
Authority Authority
A B
Purchase Response
Merchant Cardholder
Purchase Request
Authorization Request
Payment
Gateway
Authorization Response
Issue SSL SET