【24h】

Secure Upgrade of Hardware Security Modules in Bank Networks

机译:安全升级银行网络中的硬件安全模块

获取原文
获取原文并翻译 | 示例

摘要

We study the secure upgrade of critical components in wide networked systems, focussing on the case study of PIN processing Hardware Security Modules (HSMs). These tamper-resistant devices, used by banks to securely transmit and verify the PIN typed at the ATMs, have been shown to suffer from API level attacks that allow an insider to recover user PINs and, consequently, clone cards. Proposed fixes require to reduce and modify the HSM functionality by, e.g., sticking on a single format of the transmitted PIN or adding MACs for the integrity of user data. Upgrading HSMs worldwide is, of course, unaffordable. We thus propose strategies to incrementally upgrade the network so to obtain upgraded, secure subnets, while preserving the compatibility towards the legacy system. Our strategies aim at finding tradeoffs between the cost for special "guardian" HSMs used on the borderline between secure and insecure nodes, and the size of the team working in the upgrade process, representing the maximum number of nodes that can be simultaneously upgraded.
机译:我们研究了广域网系统中关键组件的安全升级,重点是PIN处理硬件安全模块(HSM)的案例研究。这些防篡改设备已被银行用来安全传输和验证在ATM上键入的PIN的能力,受到API级别的攻击,使内部人员可以恢复用户PIN,从而克隆卡。提议的修复方法需要例如通过坚持所传输的PIN的单一格式或添加MAC来减少和修改HSM功能,以确保用户数据的完整性。当然,在全球范围内升级HSM的费用是无法承受的。因此,我们提出了对网络进行增量升级的策略,以便获得升级后的安全子网,同时保留与传统系统的兼容性。我们的策略旨在在安全和不安全节点之间的边界上使用特殊的“监护人” HSM的成本与升级过程中工作团队的规模(代表可以同时升级的最大节点数量)之间进行权衡。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号