Certificates are issued hierarchically starting with a root certificate known to all SET software |
Each certificate is signed with private key of parent. The root is self signed |
GCA = Geopolitical CA |
CCA = Cardholder CA |
PCA = Payment Gateway CA |
MCA = Merchant CA |
CA = Certificate Authority |
Root |
Brand |
GCA |
CCA |
MCA |
PCA |
Cardholder Signature |
Merchant Signature |
Merchant Key Exchange |
Payment Gateway Key Exchange |
Payment Gateway Signature |
E.g. Visa Mastercard |