资源描述:
《etc系统中金融ic卡安全性分析与实践》由会员上传分享,免费在线阅读,更多相关内容在学术论文-天天文库。
1、-------上海交通大学工程硕士学位论文ABSTRACTRESEARCHANDPRACTICEONSECURITYOFFINANCIALICCARDOFETCABSTRACTWiththedevelopmentofChina'sGoldencardproject,banksbegintoissuefinancialICcardsinsteadofmagneticstripecards,andintroducedmanyapplicationsbasedonit.InadditiontothebasicfunctionssuchasdepositandPOSpurchase,wecan
2、alsomakeourselvestakebus,shopping,andmakeanappointmentinhospitaljustbyusingfinancialICcards.ETCtrafficcardisthetypicalfinancialICcardapplicationinrecentyears.Nowadays,it’sdifferentfromthepastthatwegettheETCtrafficcardfromHighwayAdministration,thankstothecooperationbetweenbanksandHighwayAdministr
3、ation,afinancialICcardcansolvetheproblem.FinancialICcardsbecamemorepowerful,applicationsarebecomingmoreandmorepopular,andinformationsecurityforICcardattackshasbecomeincreasinglyprominent.Whichmainlyabouttwoaspects,ononehand,thesecuretransmissionoftransactioninformationbetweentradingterminals,ont
4、heotherhand,authentication.ThispapermainlydiscussedfinancialICcard’sapplicationinETCsystem,focusonmulti-systeminformationsecuritybetweenETCsystemandbank’sICcardsystem.BasedonanalysisofthePBOCstandardencryptionalgorithms,thispaperproposethatapplytheChinesecommercialencryptionstandardalgorithminth
5、eprotectionofICcardinformationsecurity.Meanwhile,thispaperanalyzedthedefectandpotentialrisksabouton-boardunits(OBU)andICcardIII-----------上海交通大学工程硕士学位论文ABSTRACTauthenticationprocess,proposedsomeprevensionmeasures.Intheend,
accordingtotheauthor'sworkingbackground,thispaperprovidean
implementation
6、plan,theICcardnamed"Longyuantransportationcard”,
whichisjointlyissuedbyHighwayAdministrationofXXprovinceandlocal
XXcommercialbank.Thecontributionofthispaperisasfollowing:1.OnthebasisofanalysisandcomparisonofPBOC2.0andPBOC3.0,
thispaperpointoutthenecessityofadoptingPBOC3.0standardsinthe
construct
7、ionoftheETCsystem.ConsideringPBOC3.0standardisnotan
compulsoryrequirement,sotheauthorputittoaforward-lookingdesignthat
usingtheChinesecommercialencryptiontoensuretheinformationsecurity
ofETCcards.SM2,SM3forthelegitimacyofICc