|
This article is cited in 1 scientific paper (total in 1 paper)
On cryptographic properties of the $CVV$ and $PVV$ parameters generation procedures in payment systems
L. R. Ahmetzyanova, E. K. Alekseev, G. A. Karpunin, S. V. Smyshlyaev CryptoPro LLC, Moscow
Abstract:
Two important mechanisms to provide security of payment systems are the checks made with parameters $CVV$ and $PVV$. In the current paper the provable security approach is exploited to analyze the two-pass decimalization procedure used, for example, by VISA. It is shown that the standard method of upper estimating the insecurity does not allow to claim security of this procedure since it provides not very good bounds for probabilistic characteristics of practical parameters. Therefore this procedure is not recommended to be used in the MIR payment system. We propose a simple procedure as a replacement that turns out to be much more secure.
Key words:
transaction security, payment systems, adversary models, provable security, security estimates.
Received 06.II.2017
Citation:
L. R. Ahmetzyanova, E. K. Alekseev, G. A. Karpunin, S. V. Smyshlyaev, “On cryptographic properties of the $CVV$ and $PVV$ parameters generation procedures in payment systems”, Mat. Vopr. Kriptogr., 9:2 (2018), 23–46
Linking options:
https://www.mathnet.ru/eng/mvk250https://doi.org/10.4213/mvk250 https://www.mathnet.ru/eng/mvk/v9/i2/p23
|
|