【24h】

TLS client handshake with a payment card

机译:带有支付卡的TLS客户端握手

获取原文

摘要

Transport Layer Security (TLS) is the de facto standard for preventing eavesdropping, tampering or message forgery of higher-risk Internet communications, for example when making a payment. At heart TLS is a stateful cryptographic protocol built around a public key infrastructure (PKI). However TLS is configurable; at one extreme it provides little protection and at the other end of the scale it provides protection against most threats to an Internet communication. In practice the ldquoIrdquo part of PKI is often not available at the client end so only the server end is authenticated. In this paper an optional TLS extension is proposed that dispenses with the need for the client to be registered with a PKI registration authority and instead uses a payment card to authenticate the user. This facilitates wider use of the available TLS services and can provide additional security services: enhanced privacy and certain non-repudiation services, for example.
机译:传输层安全性(TLS)是事实上的标准,用于防止窃听,篡改或伪造高风险Internet通信(例如在付款时)。 TLS的本质是围绕公钥基础结构(PKI)构建的有状态加密协议。但是TLS是可配置的。一方面,它提供的保护很少,而另一方面,它提供了针对大多数Internet通信威胁的保护。实际上,PKI的ldquoIrdquo部分通常在客户端不可用,因此仅对服务器端进行身份验证。在本文中,提出了一个可选的TLS扩展,该扩展免除了使用PKI注册机构注册客户端的需求,而是使用支付卡来验证用户身份。这有助于更广泛地使用可用的TLS服务,并可以提供其他安全服务:例如,增强的隐私性和某些不可否认的服务。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号