首页> 外文会议>IEEE Symposium on Security and Privacy >On two proposals for on-line bankcard payments using open networks: problems and solutions
【24h】

On two proposals for on-line bankcard payments using open networks: problems and solutions

机译:在使用开放网络的两项建议上,使用开放网络:问题和解决方案

获取原文

摘要

Recently, two major bankcard payment instrument operators VISA and MasterCard published specifications for securing bankcard payment transactions on open networks for open scrutiny. (VISA: Secure Transaction Technology, STT; MasterCard: Secure Electronic Payment Protocol, SEPP.) Based on their success in operating the existing on-line payment systems, both proposals use advanced cryptographic technologies to supply some security services that are well-understood to be inadequate in open networks, and otherwise specify systems similar to today's private-network versions. In this paper we reason that when an open network is used for underlying electronic commerce some subtle vulnerabilities will emerge and the two specifications are seen not in anticipation of them. A number of weaknesses are found as a result of missing and misuse of security services. Missing and misused services include: authentication, nonrepudiation, integrity, and timeliness, We identify problems and devise solutions while trying to keep, the current successful working style of financial institutions being respected.
机译:最近,两个主要的银行卡支付仪器运营商Visa和Mastercard发布了在开放式审查的开放网络上确保银行卡支付交易的规范。 (VISA:安全事务技术,STT;万事达卡:安全电子支付协议,SEPP。)根据他们在运营现有的在线支付系统方面的成功,这两个建议都使用先进的加密技术来提供众所周知的安全服务在开放网络中不适当,否则指定类似于当今私有网络版本的系统。在本文中,我们推理的是,当开放网络用于基础电子商务时,一些微妙的漏洞将出现,并且可以看到两种规格并未预期。由于缺失和滥用安全服务而发现了许多弱点。缺失和误用的服务包括:认证,非分析,完整性和及时性,我们发现问题和设计解决方案,同时试图保持,当前正在尊重的金融机构成功的工作方式。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号