SWAPEROO
A Simple Wallet Architecture for
Payments, Exchanges, Refunds,
and Other Operations
Neil Daswani, Dan Boneh, Hector
Garcia-Molina, Steven Ketchpel,
Andreas Paepcke
Stanford University
1
Goals
Desirable wallet properties / features
Define wallet interaction model
Define Clean APIs for wallet and its
components
Build Prototype
2
Wallet Features
Extensible: support multiple existing and newly
developed instruments and protocols
Non-Web-Centric: can be implemented in non-
web environments; extensibility across devices
Symmetric: common services across commerce
applications; extensibility across commerce
applications
Client-Driven: user initiates all operations,
including wallet invocation
3
An Example
Session Initiation
Dilbert -> [Link]
Instrument Class Negotiation
Dilbert: MasterCard,
PonyCash, CyberCoin
[Link]: MasterCard,
VISA, CyberCoin
==> MasterCard, CyberCoin
4
An Example
Protocol Negotiation for MasterCard
Dilbert: SET (2KP)
[Link]: SET (2KP), SET (3KP),
or Unencrypted
==> SET (2KP)
Protocol Selection: SET (2KP)
Available Operations: PAY, CREDIT
5
An Example
Instrument Instance Selection:
Dilbert’s Citibank MasterCard
Transaction Execution
SET (2KP) PAY
Close Session
6
SWAPEROO Architecture
User Profile Manager User User
Interface Interface
API
Instrument
Manager
Wallet
Controller Client
Instrument API
Instances
Protocol
Protocols
Manager
Communication Manager
7
Function Descriptions
Instrument Manager: encryption of
instruments
Protocol Manager: protocol invocation
Communication Manager: low-level,
synchronous messaging
User Profile Manager: stores access
control information
Wallet Controller: coordinates wallet
operations & enforces access control
8
Symmetric Vendors/Banks
Vendor Wallet Bank Wallet
Customer Profile Manager UI Account Profile Manager UI
Instrument Instrument
Manager Manager
Vendor Bank
Controller Controller
Protocol Protocol
Manager Manager
Communication Manager Communication Manager
9
Wallet Interaction Model
Open
Session
Open Session
Instrument Class
Negotiation
Instrument Class
Protocol
Negotiation
Negotiation
Protocol
Protocol Negotiation
Selection
Protocol Selection
Instrument
Selection Instrument Selection
Transaction Transaction Execution
Execution
Close
Close Session
Session 10
Wallet Interaction Model
Open
Session
Open Session
Instrument Class
Negotiation
Instrument Class
Protocol
Negotiation Negotiation
Protocol Protocol Negotiation
Selection
Protocol Selection
Instrument
Selection Instrument Selection
Transaction Transaction Execution
Execution
Close
Close Session
Session 11
Instrument Class Negotiation
User Wallet Vendor Wallet
User Profile Manager UI Customer Profile Manager UI
Instrument Instrument
Manager Manager
Wallet Vendor
Controller Controller
Protocol Protocol
Manager Manager
Communication Manager Communication Manager
12
Wallet Interaction Model
Open
Session
Open Session
Instrument Class
Negotiation Instrument Class Negotiation
Protocol
Negotiation
Protocol Negotiation
Protocol Protocol Selection
Selection
Instrument Selection
Instrument
Selection Transaction Execution
Transaction
Execution
Close Session
Close
Session 13
Transaction Execution
User Wallet Vendor Wallet
User Profile Manager UI Customer Profile Manager UI
Instrument Instrument
Manager Manager
Wallet Vendor
Controller Controller
Protocol Protocol
Manager Manager
Communication Manager Communication Manager
14
Transaction Execution
End-User Wallet Vendor Wallet
User Wallet User Profile SET SET Wallet Vendor
Application Controller Manager Protocol Protocol Controller Application
subscribe
(EXECUTE_TRANSACTION)
executeTransaction(inv,
Citibank Mastercard,PAY)
checkPrivileges (inv,
Citibank Mastercard, PAY)
OK
EXECUTE TRANSACTION SETProtocol2KP PAY
OK
doOperation(PAY,
doOperation(PAY,Citibank Mastercard,PAY) Citibank Mastercard,PAY)
notify
(EXECUTE_TRANSACTION)
15
Transaction Execution
16
Trade-offs / Issues
Where to put what functionality?
User Profile Manager User User
Interface Interface
API
Instrument Manager
Wallet Client
Instrument Controller API
Instances
Protocol Manager
Protocols
Communication Manager
17
Trade-offs / Issues
User Interaction Open
Session
number of steps vs. Instrument Class
Negotiation
likelihood of an error
Protocol
Negotiation
Protocol
Selection
Instrument
Selection
Transaction
Execution
Close
Session
18
Trade-offs / Issues
Security vs. Customization
i.e., User Interface & UI API
User Profile Manager User User
Interface Interface
API
Instrument
Manager
Wallet
Client
Instrument Controller
API
Instances
Protocol
Protocols Manager
Communication Manager
19
Implementation &
Future Work
Implementation
C++ (PalmOS)
Java (Windows)
PonyCash
Future Work
Populate the wallet
Experiment with other devices/environments
(i.e. smart cards, mobile phones, web, etc.)
Abstract Data Manager
20
Summary / Contributions
Desirable wallet properties: extensibile,
symmetric, non-web-centric, client-driven
Defined wallet interaction model
Clean APIs for wallet and its components
Prototype Implementation in Java & C++
(available at [Link]
21