Personal Information Access Control Scheme for Secure NFC Integrated Payment

NFC integrated payment service generates information such as user consumption-migration information by processing them through big-data technology after collecting personal information including credit card payment information, location information, electronic coupon usage history, etc. and also provides such service as advertising tailored to a specific user based on the pattern information. Since such sensitive personal information as consumption pattern in addition to simple personal information, only those authorized companies should be able to process the information thereof. Nonetheless, the cooperative relationship for sharing personal information among the companies based on TSM just like a mesh has been formed; thus, it is difficult to control access to personal information. Moreover, as for Hadoop that is the most prominent big-data technology, it has an access control function; however, it lacks a method to grant an authority to process personal information. As a result, it is not able to grant an authority to process information in accordance with the companies to provide simple services using the pattern information and the companies to process personal information for generating pattern information. Thus, this paper proposed a technique for key generation and distribution and a secure communication protocol in order to ensure that access control of personal information and personal information processing for each authority will be securely conducted in NFC integrated payment environment.