Lecture Notes in Computer Science, 2002, Volume 2339/2002, 196-209, DOI: 10.1007/3-540-46088-8_18

Off-Line Generation of Limited-Use Credit Card Numbers

Aviel D. Rubin and Rebecca N. Wright

View Related Documents

Abstract

Recently, some credit card companies have introduced limited-use credit card numbers—for example, American Express’s single-use card numbers and Visa’s gift cards. Such limited-use credit cards limit the exposure of a traditional long-term credit card number, particularly in Internet transactions. These offerings employ an on-line solution, in that a credit card holder must interact with the credit card issuer in order to derive a limited-use token. In this paper, we describe a method for cryptographic off-line generation of limited-use credit card numbers. This has several advantages over the on-line schemes, and it has applications to calling cards as well. We show that there are several trade-offs between security and maintaining the current infrastructure.

Fulltext Preview

Image of the first page of the fulltext document