• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2012, Vol. 34 ›› Issue (12): 22-26.

• 论文 • 上一篇    下一篇

微支付协议Millicent的改进与模型检测

周璇,汪学明   

  1. (贵州大学计算机科学与信息学院,贵州 贵阳 550025)
  • 收稿日期:2011-10-31 修回日期:2012-03-19 出版日期:2012-12-25 发布日期:2012-12-25
  • 基金资助:

    国家自然科学基金资助项目[2011]61163049号;贵州省自然科学基金项目黔科合J字[2011]2197号

Improvement and Model Checking of Micro-Payment Protocol Millicent

ZHOU Xuan,WANG Xueming   

  1. (College of Computer Science and Information,Guizhou University,Guiyang 550025,China)
  • Received:2011-10-31 Revised:2012-03-19 Online:2012-12-25 Published:2012-12-25

摘要:

为解决传统移动微支付协议因注重效率而导致协议存在安全隐患的缺陷,根据移动电子商务所应具备的安全性,通过对移动微支付协议Millicent的研究,发现其存在严重的用户欺骗问题。针对该协议存在的不足,增加商家与用户间的确认过程,使协议具有不可否认性。最后,对改进的移动微支付协议Millicent建模并使用SMV模型检测工具进行分析。分析结果表明,改进的协议除具有原协议的保密性和认证性外还具有不否认性和公平性,相比原协议更优越。

关键词: 微支付, 不可否认性, 公平性, 模型检测, 协议分析

Abstract:

To solve the defect of the potential security risk caused by emphasizing the efficiency in the traditional mobile micropayment protocol, according to the security that the mobile electronic business should have, the paper studies the mobile micropayment protocol Millicent and discovers that it cheats customers. For the sake of the shortage, increasing the confirmation process between Vendor and Custom makes the protocol nonrepudiate. Finally, the improved mobile micropayment protocol Millicent is modeled and is analyzed with the model checking tool SMV. The analysis results show that the improved protocol owns nonrepudiation and fairness besides possessing private and authenticating of the former, so it is better.

Key words: micropayment;nonrepudiation;fairness;model checking;protocol analysis