作者: Adam Wójtowicz , Jacek Chmielewski
DOI: 10.1007/S00779-017-1035-Z
关键词: Authorization certificate 、 System deployment 、 Protocol (object-oriented programming) 、 Mobile computing 、 Context (language use) 、 Computer security 、 Technical feasibility 、 Computer science 、 Identification (information) 、 Payment
摘要: In this work, the technical feasibility of passive secure payments for brick-and-mortar points sale is analyzed. The core element proposed approach a new application context-based risk and trust assessment. It allows dynamic selection payment authorization methods that constitutes accurate trade-off between security convenience. Particularly, can be performed authorized in background using biometric means (face recognition), without user’s explicit action. Generally, approach, multiple devices are used authorization: mobile, wearables, or stationary, client’s seller’s, used: biometric, knowledge-based, possession-based. reported research includes requirement identification, novel architecture protocol proposition, proof-of-concept prototype system deployment, evaluation-based lessons learned. confirms with it possible to take advantage client-seller dynamism simplify process while maintaining level.