SECURING PAYMENT TRANSACTION QR CODE BASED WITH MUTUAL AUTHENTICATION USING PUBLIC KEY INFRASTRUCTURE

<p align="justify">QR code can be used in mobile commerce transactions because QR code stores more information than other barcode types. On the other hand, attackers can commit fraud against users of QR code-based payment systems. Fraud is done by creating a fake QR code and the orig...

Full description

Saved in:
Bibliographic Details
Main Author: SORAYA - NIM: 23516077 , ASTRID
Format: Theses
Language:Indonesia
Online Access:https://digilib.itb.ac.id/gdl/view/25885
Tags: Add Tag
No Tags, Be the first to tag this record!
Institution: Institut Teknologi Bandung
Language: Indonesia
id id-itb.:25885
spelling id-itb.:258852018-07-04T09:28:44ZSECURING PAYMENT TRANSACTION QR CODE BASED WITH MUTUAL AUTHENTICATION USING PUBLIC KEY INFRASTRUCTURE SORAYA - NIM: 23516077 , ASTRID Indonesia Theses INSTITUT TEKNOLOGI BANDUNG https://digilib.itb.ac.id/gdl/view/25885 <p align="justify">QR code can be used in mobile commerce transactions because QR code stores more information than other barcode types. On the other hand, attackers can commit fraud against users of QR code-based payment systems. Fraud is done by creating a fake QR code and the original QR code is replaced with a fake QR code so the buyer sends the balance of money to the attacker, not to the seller. This study aims to build a payment system based on QR code that can mutually authenticate buyer and seller identity by using Public Key Infrastructure. <br /> <br /> <br /> <br /> <br /> Information on ordered goods are secured in QR code. To maintain the confidentiality of the QR code, the data content is encrypted using symmetric keys and the symmetric key is wrapped by using public key. Digital signature of information on ordered goods is also included. The authentication stage is performed by unwrapping the symmetric key by using private key. The decrypted data is then checked by the server to find out whether the ordered item is eligible to be paid or not. Then, the digital signature is verified using the public key. The mutual authenication stage is mutually done by buyers and sellers. <br /> <br /> <br /> <br /> <br /> System testing was done with two types of testing namely functional testing and scenario testing. QR code-based payment system could implement Public Key Infrastructure (PKI) to provide mutual authentication stage and secure QR code data content. The system could also check whether the QR code, displayed by the buyer or seller, was fake or not. The system can also prevent customers from making payment confirmations of items ordering that are not valid due to failed authentication stages or the ordering goods itself has been previously paid.<p align="justify"> text
institution Institut Teknologi Bandung
building Institut Teknologi Bandung Library
continent Asia
country Indonesia
Indonesia
content_provider Institut Teknologi Bandung
collection Digital ITB
language Indonesia
description <p align="justify">QR code can be used in mobile commerce transactions because QR code stores more information than other barcode types. On the other hand, attackers can commit fraud against users of QR code-based payment systems. Fraud is done by creating a fake QR code and the original QR code is replaced with a fake QR code so the buyer sends the balance of money to the attacker, not to the seller. This study aims to build a payment system based on QR code that can mutually authenticate buyer and seller identity by using Public Key Infrastructure. <br /> <br /> <br /> <br /> <br /> Information on ordered goods are secured in QR code. To maintain the confidentiality of the QR code, the data content is encrypted using symmetric keys and the symmetric key is wrapped by using public key. Digital signature of information on ordered goods is also included. The authentication stage is performed by unwrapping the symmetric key by using private key. The decrypted data is then checked by the server to find out whether the ordered item is eligible to be paid or not. Then, the digital signature is verified using the public key. The mutual authenication stage is mutually done by buyers and sellers. <br /> <br /> <br /> <br /> <br /> System testing was done with two types of testing namely functional testing and scenario testing. QR code-based payment system could implement Public Key Infrastructure (PKI) to provide mutual authentication stage and secure QR code data content. The system could also check whether the QR code, displayed by the buyer or seller, was fake or not. The system can also prevent customers from making payment confirmations of items ordering that are not valid due to failed authentication stages or the ordering goods itself has been previously paid.<p align="justify">
format Theses
author SORAYA - NIM: 23516077 , ASTRID
spellingShingle SORAYA - NIM: 23516077 , ASTRID
SECURING PAYMENT TRANSACTION QR CODE BASED WITH MUTUAL AUTHENTICATION USING PUBLIC KEY INFRASTRUCTURE
author_facet SORAYA - NIM: 23516077 , ASTRID
author_sort SORAYA - NIM: 23516077 , ASTRID
title SECURING PAYMENT TRANSACTION QR CODE BASED WITH MUTUAL AUTHENTICATION USING PUBLIC KEY INFRASTRUCTURE
title_short SECURING PAYMENT TRANSACTION QR CODE BASED WITH MUTUAL AUTHENTICATION USING PUBLIC KEY INFRASTRUCTURE
title_full SECURING PAYMENT TRANSACTION QR CODE BASED WITH MUTUAL AUTHENTICATION USING PUBLIC KEY INFRASTRUCTURE
title_fullStr SECURING PAYMENT TRANSACTION QR CODE BASED WITH MUTUAL AUTHENTICATION USING PUBLIC KEY INFRASTRUCTURE
title_full_unstemmed SECURING PAYMENT TRANSACTION QR CODE BASED WITH MUTUAL AUTHENTICATION USING PUBLIC KEY INFRASTRUCTURE
title_sort securing payment transaction qr code based with mutual authentication using public key infrastructure
url https://digilib.itb.ac.id/gdl/view/25885
_version_ 1822921705458237440