首页> 外文OA文献 >Design and development of an on-line vending system for selling prepaid electricity via the Internet
【2h】

Design and development of an on-line vending system for selling prepaid electricity via the Internet

机译:设计和开发通过互联网销售预付费电力的在线自动售货系统

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

The sale of prepaid electricity is prevalent in South Africa due to the current economic, social, and political conditions. The system currently used for the distribution of tokens for prepaid electricity, CVS, has a design flaw that leads to many security vulnerabilities. The design flaw is that the security devices that generate the tokens are distributed in the field and operate independently of centralised control. This was done because of the limited communication infrastructure in South Africa 10 years ago, but is no longer necessary. An improvement to the system is suggested that removes the security vulnerabilities by making the system on-line. By employing the communication infrastructure that is available today to provide access to the security devices, the security devices can be located in a secure environment. Changing the mode of operation to on-line also has other advantages such as simplifying auditing and removing synchronisation problems. This improved system works by communicating on-line with a centralised server and database for every transaction that a customer makes. By doing this, all of the parties involved are kept up to date with the most recent transactions. There can no longer be financial discrepancies and the risk of all parties involved is thus reduced. It is no longer meaningful to steal the vending machines because they no longer have the ability to generate tokens independently. In order to implement such a system, however, there are many security aspects that need to be addressed, such as the confidentiality of the information within the system and proving that a transaction did occur between two specific parties. To this end, cryptographic functions and protocols are selected that meet the requirements of the system. Public key cryptography was found to be a necessary ingredient in making the system work effectively and efficiently. In order to use public key cryptography in the new system, Public Key Infrastructure is required to manage public keys and provide authentication services. A suitable system is developed and described that employs certificate authorities and X.509 certificates. The procedures that are required from each party are listed. A set of messages that is required for the functions of the system is given. For each message, the contents of the message is given, the parts of the message that must be encrypted are defined and the parts of the message that must be digitally signed are given. Finally, the security of the individual parts of the system is critically analysed to show that all of the design goals have been achieved. Particular attention is given to the authentication of parties involved in the communication. The security of the system as a whole is also evaluated with respect to the X.810 security framework and it is shown that the system is robust from a security perspective. The result of the research is a system that meets the required functionality to replace the existing system, and at the same time meets all of the security requirements. It is shown that the proposed system does not have the security flaws of the existing system and thus is more effective in its purpose of vending prepaid electricity.
机译:由于当前的经济,社会和政治条件,预付费电力的销售在南非很普遍。当前用于预付费电力令牌分配的系统CVS具有设计缺陷,导致许多安全漏洞。设计缺陷在于,生成令牌的安全设备分布在现场,并且独立于集中控制进行操作。这样做是因为10年前南非的通信基础设施有限,但不再需要。建议对该系统进行改进,以使系统联机来消除安全漏洞。通过使用当今可用的通信基础结构来提供对安全设备的访问,可以将安全设备放置在安全的环境中。将操作模式更改为联机还具有其他优势,例如简化审核和消除同步问题。这个改进的系统通过与客户进行的每笔交易的集中服务器和数据库进行在线通信来工作。这样,所有相关方都可以及时了解最新交易。不再存在财务差异,从而降低了所有相关方的风险。窃取自动售货机不再有意义,因为它们不再具有独立生成令牌的能力。但是,为了实现这样的系统,有许多安全方面需要解决,例如系统内信息的机密性以及证明交易确实在两个特定方之间发生。为此,选择满足系统要求的密码功能和协议。发现公钥密码术是使系统有效运行的必要组成部分。为了在新系统中使用公共密钥加密,需要公共密钥基础结构来管理公共密钥并提供身份验证服务。开发并描述了使用证书颁发机构和X.509证书的合适系统。列出了各方要求的程序。给出了系统功能所需的一组消息。对于每个消息,给出消息的内容,定义必须加密的消息部分,并给出必须进行数字签名的消息部分。最后,对系统各个部分的安全性进行严格分析,以表明已实现所有设计目标。特别注意通信中有关各方的身份验证。还相对于X.810安全框架评估了整个系统的安全性,从安全性的角度来看,该系统是可靠的。研究的结果是,一个系统可以满足替换现有系统所需的功能,并同时满足所有安全性要求。结果表明,所提出的系统不存在现有系统的安全缺陷,因此在售卖预付费电力方面更加有效。

著录项

  • 作者

    Hearn, Gareth;

  • 作者单位
  • 年度 2006
  • 总页数
  • 原文格式 PDF
  • 正文语种
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号