Kommunikatsioonimudel
purchases nor if the company is a reliable merchant. Similar problem with client authorisation
- the client certificate does not tie a person to a specific authorized payment card; thus the
company has no assurance that the person is authorized to make a payment card purchase.
Secure Electronic Transactions (SET)
Designed for payment card transactions over the Internet. Provides security services among 3
players: customer, mercahnt, merchant's bank. All must have certificates. SET specifies legal
meanings of certificates - appointment on liabilities for transactions. Customer's card number
passed to merchant's bank without merchant ever seeing number in plain text - prevent
mercahnts from stealing, leaking payment card numbers. Three software components -
browser wallet, merchant server, acquirer gateway.
46
67