With the development of the online trade the threatened environment is rapidly developing. The biggest number of e-fraud is related to the theft of personal ID and credit card information. The transfer of credit card numbers over the internet from the web browser to shopping sites allows easily process the fraudulent actions as most of the online shopping sites usually require one step-authentication process: performance of the credit card number and zip code that is usually sufficient to validate the sale. The things are even easier to crack as information stored in the merchant's data base is unencrypted.
The researchers at Anglia Ruskin University, in Chelmsford came up with an idea of a disposable credit card number (DCCN) that might be the best preventive method to the online fraud. DCCNs supposedly would be generated "off-line" by the mean of a pre-shared secret key known only to the issuer and the customer and applicable for a single use. It would abolish the necessity to pass through open channels of Internet the credit card details to create the voucher code. As it was assumed the off-line generation of DCCNs is the most simple and effective idea to add an additional protection level to the e-commerce platform that together with DCCNs creates the Private Payment and Secure Click.
During the off-line generation of DCCNs, the client simply registers the card with the issuer and receives the associated secret key. After all the client will use it in conjunction with a smart card, PDA or mobile phone in order to generate an encrypted code (hash) based on the price of goods or services the customer plans to purchase.
The resulting hash is than adapted to generate DCCN, forwarded to the merchant. The shopping site will accept the DCCN as any ordinary credit card number. So the client will ensure that his ID and credit card details are not accessible to any cybercriminal. It is old as the world that the best "weapon" against the online fraud to isolate the sensitive data base from the open Internet channel. It seems that despite the complexity of the process of generation of DCCN the tremendous annual losses from online fraud worth it, aren't they?
Natalia, reporter of Ecommerce Journal
Share this story
What are these?