1
1
10101010010001001101001112012-08-23 07:45:17
Electronic digital signature
1010101001000100110100111, 2012-08-23 07:45:17

Are there electronic payment systems with the possibility of offline preparation of payment orders?

I do not trust any modern electronic payment system (in view of their a priori leakiness ).
For a long time I dreamed of finding a bank or a payment system with the ability to send a request for the execution of a payment order to a processing center through open communication channels over an insecure network.

What do we have?

To prepare a payment order, we will use an old computer disconnected from the Internet and other networks (for example, the first stump with 16 mega RAM, a 2 gigabyte screw, 98 Windows, and a 1 mega vidyuha, and, optionally, FDD for at least some- connection with the "outside world").

From the keyboard, we “drive in” the payment details (account numbers, amounts, purpose of payments, etc.).
The output is a URL-like string containing all the data.

We transfer this URL (or its hash) to an isolated computer and sign it with a private key (which we can store, for example, in a safe on the same FDD).

We safely transfer the received signature file to any other unprotected computer (it is possible that it is even infected with viruses and trojaned to the eyeballs) We attach

the signature to our payment.

We send the signed payment order to the bank for execution via an open unsecured channel (if necessary, having previously encrypted it with the bank's public key, if confidentiality is important to us).

The bank in response sends us 1 bit of information (signed by the bank's EDS) containing information about whether the transaction went through or not (if necessary, by encrypting the response with our public key, for example, if we sent the encrypted request ourselves).

Has anyone ever experienced something similar?

Answer the question

In order to leave comments, you need to log in

2 answer(s)
A
Antonio43, 2012-08-23
@Antonio43

There is nothing like what you describe. We use the VTB telebank in the office.
For reliability, we use two signatures (chief accountant and general director). These are two separate accounts, each with its own digital signature certificate, login and password. No document will be executed by the bank without two signatures. To enter the bank, you additionally use a one-time SMS code sent to your mobile phone.
We prepare all payments offline. Then we upload them to the bank via an XML file.

M
MusicMan67, 2012-08-23
@MusicMan67

Previously, our payment orders were formed on offline machines in the “payment order” program. They were dumped on a floppy disk and transferred to a laptop with the RCC transport system. The file was delayed and confirmation came, in view of the statuses "Transferred to the transport system", "In processing", "Completed". In principle, there is nothing complicated. You can sign both offline machines and online. You can sign on one machine by installing the necessary certificates from rutokens.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question