Wang, Hua and Cao, Jinli and Zhang, Yanchun (2002) A flexible payment scheme and its user-role assignment. In: Chan, Alvin and Chan, Stephen and Leong, Hong and Ng, Vincent, (eds.) Cooperative internet computing. Springer (Kluwer Academic Publishers), pp. 107-128.
|HTML Citation||EndNote||Dublin Core||Reference Manager|
Full text available as:
|PDF (Accepted Version - Chapter 7) - Requires a PDF viewer such as GSview, Xpdf or Adobe Acrobat Reader|
A flexible payment scheme and its role-based user-role assignments are proposed in this paper. The scheme uses electronic cash for payment transactions. In this new protocol, from the viewpoint of banks, consumers can improve anonymity if they are worried about disclosure of their identities. A new role called anonymity provider agent (AP) provides a high anonymous certificate. The role AP certifies re-encrypted data after verifying the validity of the content from consumers, but with no private information of the consumers required. With this new method, each consumer can get a required anonymity level, depending on the available time, computation and cost. There are two types of problems that may arise in user-role assignments. One is related to authorization granting process. Mutually exclusive roles may be granted to a user and the user may have or derive a high level of authority. Another is related to authorization revocation. When a role is revoked from a user, the user may still have the role from other roles. To solve these problems, we first analyze the duty separation constraints of the roles and role hierarchies in the scheme, then discuss granting a role to a user, weak revocation and strong revocation for the scheme.
|Item Type:||Book Chapter (Commonwealth Reporting Category B)|
|Additional Information:||Chapter 7. Accepted version deposited in accordance with the copyright policy of the publisher. Electronic version of book available via USQ Library catalogue.|
|Uncontrolled Keywords:||payment scheme, authorization, RBAC, AP agent|
|Fields of Research (FOR2008):||08 Information and Computing Sciences > 0806 Information Systems > 080608 Information Systems Development Methodologies|
|Socio-Economic Objective (SEO2008):||UNSPECIFIED|
|Deposited On:||30 Mar 2011 17:44|
|Last Modified:||29 Aug 2012 13:09|
Archive Staff Only: edit this record