首页> 外文会议> >Pocket device for authentication and data integrity on Internet banking applications
【24h】

Pocket device for authentication and data integrity on Internet banking applications

机译:用于Internet银行应用程序上的身份验证和数据完整性的袖珍设备

获取原文

摘要

During the last decades we have witnessed an exponential growth of the number of computer viruses. However, the real threat we are now facing is not so much the fact that a virus can make thousands of copies of itself in our computer, but the wide range of things they can do with the data stored or processed in it. One field in which this fact should be considered with special care is electronic banking. These online services are normally accessed from personal computers with low protection. The operating systems used on these computers tend to sacrifice the security on behalf of the commodity of the user. Under such circumstances, it would be rather easy to implement a man-in-the-middle attack in order to intercept the data exchanged with the bank. This way an attacker could end up controlling the money in our bank accounts. In order to illustrate this assertion, we outline some possible attacks that can break the security of several security systems, from passwords authentication to smart cards. The conclusion that we extract from here is that we cannot trust our computers: The data we input on the computer can be stolen, the data exchanged with other computers on the Web can also be intercepted and even modified, and the output we get from the computer monitor may not correspond to the data it is about to process and send in our name. Therefore, an trusted device is needed when performing banking operations over the Internet. Here we propose a digital signer device that not only provides a tamper proof storage for the digital signature but also provides its own display and keyboard. This system improves the security of smart cards by avoiding its dependence on the computer to interface with the user, making it immune to virus attacks.
机译:在过去几十年中,我们目睹了计算机病毒数量的指数增长。然而,我们现在面临的真正威胁并不是那么virus可以在我们的计算机中赚取数千份副本,但它们可以处理存储或处理的数据的广泛的东西。应该用特别护理考虑这一事实的一个领域是电子银行。这些在线服务通常从具有低保护的个人计算机访问。这些计算机上使用的操作系统倾向于代表用户的商品牺牲安全性。在这种情况下,实施一个中间人攻击是相当容易的,以便拦截与银行交换的数据。这样,攻击者最终可能会在银行账户中控制资金。为了说明这种断言,我们概述了可能会破坏若干安全系统安全性的一些可能的攻击,从密码认证到智能卡。我们从这里提取的结论是我们无法信任我们的计算机:我们在计算机上输入的数据可以被盗,与Web上的其他计算机交换的数据也可以截获,甚至修改,我们从中得到的输出计算机显示器可能与其上即将处理的数据相对应,并以我们的名义发送。因此,在通过互联网上执行银行业务时需要可信设备。在这里,我们提出了一种数字签名者设备,不仅为数字签名提供了篡改证明存储,而且还提供了自己的显示和键盘。该系统通过避免其对计算机与用户界面的依赖来提高智能卡的安全性,使其免受病毒攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号