首页> 外文OA文献 >e-EMV: Emulating EMV for Internet payments using Trusted Computing technology
【2h】

e-EMV: Emulating EMV for Internet payments using Trusted Computing technology

机译:e-EMV:使用可信计算技术为互联网支付模拟EMV

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

The introduction of Static Data Authentication (SDA) compliant EMV cards with their improved cardholder verification and card authentication capabilities has resulted in a dramatic reduction in the levels of fraud seen at Point of Sale (POS) terminals. However, with this POS-based reduction has come a corresponding increase in the level of fraud associated with Internet-based Card Not Present (CNP) transactions. This increase is largely attributable to the fact that Internet-based CNP processing has no easy way of integrating EMV into its transaction architecture. In this regard, payment is reliant on Mail Order Telephone Order (MOTO) based processing where knowledge of card account details is deemed a sufficient form of transaction authorisation.This report aims to demonstrate how Trusted Computing technology can be used to emulate EMV for use in Internet-based CNPtransactions. Through a combination of a Trusted Platform Module, processor (with chipset extensions) and OS support we show how we can replicate the functionality of standard EMV-compliant cards. The usage of Trusted Computing in this setting allows a direct migration to more powerful Combined DDA and application cryptogram generation (CDA) cards as well as offering increased security benefits over those seen in EMV's deployment for POS transactions. Customer to Merchant interaction in our setting mirrors transaction processing at traditional POS terminals. We build upon the services offered by Trusted Computing in order to provide a secure and extensible architecture for Internet-based CNP transactions.
机译:引入符合静态数据身份验证(SDA)的EMV卡及其改进的持卡人验证和卡身份验证功能,已导致销售点(POS)终端上的欺诈水平大大降低。但是,随着基于POS的减少,与基于Internet的卡不存在(CNP)交易相关的欺诈水平也相应增加。这种增长主要归因于基于Internet的CNP处理没有简单的方法将EMV集成到其事务体系结构中。在这方面,付款依赖于基于邮件订单电话订单(MOTO)的处理,在该处理中,对卡帐户详细信息的了解被认为是足够的交易授权形式。本报告旨在演示如何使用可信计算技术来仿真EMV以用于基于Internet的CNP事务。通过结合受信任的平台模块,处理器(具有芯片组扩展)和操作系统支持,我们将展示如何复制标准EMV兼容卡的功能。在此设置中使用Trusted Computing可以直接迁移到功能更强大的DDA和应用程序密码生成(CDA)组合卡,并且比EMV部署POS交易时看到的安全性更高。在我们的设置中,客户与商家的互动反映了传统POS终端的交易处理。我们基于Trusted Computing提供的服务,以便为基于Internet的CNP事务提供安全且可扩展的体系结构。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号