|
Secure Electronic Transaction (SET)广告 Secure Electronic Transaction (SET)The Secure Electronic Transaction? (SET?) protocol has the potential to be the secured payments product of the e-commerce age. While it hasn't been widely used to date, it has only recently emerged from the test phase with its impressive offering of significant capabilities. SET could easily become the predominant protocol for both business-to-consumer and business-to-business electronic commerce. Setting the standard
SET is basically an open technical standard for the commerce industry developed as a way to facilitate secure payment card transactions over the Internet. Digital certificates create a trust chain throughout the transaction, verifying cardholder and merchant validity, a process unparalleled by other Internet security solutions. Software vendors whose products pass SET compliance testing are eligible to display the SET Mark on their products, as are merchants, financial institutions, and promotional sites that utilize or advertise licensed software. A set apart
Set strategySET counters this threat by a requirement that all transactions be signed and identified by each participant at each step of the purchasing process. By requiring cryptographic identification, the authentication will actually surpass that of nonelectronic transactions. The extremely high fraud possibility forces merchants conducting electronic commerce with credit cards to assume the risk. Additionally, the percentage charged by the acquirer is usually significantly higher. A conventional credit card transaction is classified as a "card present" transaction and is typically subject to a 1 to 3 percent fee. The Internet classification or "card not present" fee ranges between 6 and 12 percent. As a sign of their confidence in SET's authentication technology, MasterCard and Visa have rated it with a "card present" classification, which will represent a significant cost saving to merchants. The second differentiating characteristic of the SET protocol is that the merchant never actually gets to see the credit card number. Instead, the purchaser's credit card information is sent encrypted to the merchant's bank. This system ensures that the merchant never gets an opportunity to abuse the credit card or transaction information, either deliberately or inadvertently. A third requirement of SET is that all sensitive information among all parties must be encrypted and signed. This encryption is used to achieve four goals with respect to cryptography—data confidentiality, data integrity, authentication, and nonrepudiation. Finally, because the SET protocol was designed specifically for use in financial transactions, it also supports such activities as credits, returning of goods, reversing authorizations for product unavailability, and charge-backs. These credit card situations currently cause difficulties with most payment gateways, but including them in the protocol alleviates this problem. Set differencesThe major advantage of SET over existing security systems is the addition of digital certificates that associate the cardholder and merchant with their financial institutions and the respective SET payment brands. Digital certificates are designed to reinforce existing trusted business relationships and will protect against fraud at a level existing systems don't. Despite all the fanfare surrounding SET, it is a security system with its fair share of detractors. Analysts cite the pricey implementation costs as one of the system's weakest points. Royal Bank of Canada, for example, recently forked out over $1 million for the implementation of a SET gateway. New options for handling credit card transactions over the Web are emerging as cheaper and simpler alternatives to SET. These include SSL (Secure Socket Layer) and SSL using X.509 digital certification. Because of the range of competing security products, the secure payments market seems destined to have an extremely healthy future, especially with the continued customer migration to the Internet. The extent of SET's role in all of this is hard to predict, but its success to date has been fairly promising. 如果您希望与本文章的作者或其所在机构,进一步交流,请联系:畅享网 姜小姐 jill.jiang@amteam.org | 021-51096826-112 | 在线联系 |
前沿论丛2009年第三期——知识管理..国内中小企业普遍存在管理基础薄弱、规范化程度低、信息化基础差等方面的问题,而知识管理的实施难度甚至要高于ERP的实施,因为简单的从上而下压迫式的推行只能做到知识…… |
|
|