RUS  ENG
Full version
JOURNALS // Matematicheskie Voprosy Kriptografii [Mathematical Aspects of Cryptography] // Archive

Mat. Vopr. Kriptogr., 2018 Volume 9, Issue 2, Pages 23–46 (Mi mvk250)

This article is cited in 1 paper

On cryptographic properties of the $CVV$ and $PVV$ parameters generation procedures in payment systems

L. R. Ahmetzyanova, E. K. Alekseev, G. A. Karpunin, S. V. Smyshlyaev

CryptoPro LLC, Moscow

Abstract: Two important mechanisms to provide security of payment systems are the checks made with parameters $CVV$ and $PVV$. In the current paper the provable security approach is exploited to analyze the two-pass decimalization procedure used, for example, by VISA. It is shown that the standard method of upper estimating the insecurity does not allow to claim security of this procedure since it provides not very good bounds for probabilistic characteristics of practical parameters. Therefore this procedure is not recommended to be used in the MIR payment system. We propose a simple procedure as a replacement that turns out to be much more secure.

Key words: transaction security, payment systems, adversary models, provable security, security estimates.

UDC: 519.719.2

Received 06.II.2017

Language: English

DOI: 10.4213/mvk250



Bibliographic databases:


© Steklov Math. Inst. of RAS, 2024