SSL TSL
SSL TSL
SSL TSL
NS-H0503-02/1104
The WEB is very visible. Complex software hide many security flaws. Web servers are easy to configure and manage. Users are not aware of the risks.
NS-H0503-02/1104
NS-H0503-02/1104
SSL was originated by Netscape TLS working group was formed within IETF First version of TLS can be viewed as an SSLv3.1
NS-H0503-02/1104
SSL Architecture
NS-H0503-02/1104
NS-H0503-02/1104
NS-H0503-02/1104
NS-H0503-02/1104
Handshake Protocol
The most complex part of SSL. Allows the server and client to authenticate each other. Negotiate encryption, MAC algorithm and cryptographic keys. Used before any application data are transmitted.
NS-H0503-02/1104
NS-H0503-02/1104
10
NS-H0503-02/1104
12
SET Services
Provides a secure communication channel in a transaction. Provides tust by the use of X.509v3 digital certificates. Ensures privacy
NS-H0503-02/1104
13
SET Overview
Key Features of SET: Confidentiality of information Integrity of data Cardholder account authentication Merchant authentication
NS-H0503-02/1104
14
SET Participants
NS-H0503-02/1104
15
NS-H0503-02/1104
16
Dual Signature
DS E KRc [ H ( H ( PI ) || H(OI))]
NS-H0503-02/1104
17
Payment processing
Payment processing
Payment processing
Payment Authorization: Authorization Request Authorization Response Payment Capture: Capture Request Capture Response
NS-H0503-02/1104
20