資源描述:
《移動(dòng)支付系統(tǒng)安全機(jī)制研究》由會(huì)員上傳分享,免費(fèi)在線(xiàn)閱讀,更多相關(guān)內(nèi)容在學(xué)術(shù)論文-天天文庫(kù)。
1、摘要移動(dòng)支付(MobilePayment)以其方便易行、支付成本低等優(yōu)點(diǎn)受到消費(fèi)者的歡迎,并逐漸成為一種流行的支付方式。然而,由于受無(wú)線(xiàn)環(huán)境諸多不利因素,如通信帶寬、信號(hào)干擾、網(wǎng)絡(luò)竊聽(tīng)、欺詐訪(fǎng)問(wèn)、病毒等,和移動(dòng)設(shè)備本身運(yùn)算能力低、存儲(chǔ)能力小、移動(dòng)范圍廣等特點(diǎn)的影響,原本用于在線(xiàn)支付(WiredPayment)的安全技術(shù)和機(jī)制都難于運(yùn)用到移動(dòng)支付,所以安全性成為制約移動(dòng)支付快速發(fā)展的瓶頸。盡管當(dāng)前的移動(dòng)支付多用于微支付場(chǎng)合,對(duì)安全性要求不高,但隨著電子商務(wù)的快速發(fā)展,移動(dòng)支付將逐步應(yīng)用于宏支付場(chǎng)合,對(duì)安全性的要求必然會(huì)越來(lái)越高。所以研究既安全、高效,又能提
2、供不可否認(rèn)性驗(yàn)證的移動(dòng)支付安全機(jī)制就顯得非常必要。本文基于上述認(rèn)識(shí)開(kāi)展工作:首先對(duì)移動(dòng)支付系統(tǒng)進(jìn)行了深入的理論研究,包括系統(tǒng)的架構(gòu)、產(chǎn)業(yè)鏈、業(yè)務(wù)運(yùn)作模式、系統(tǒng)功能模塊、安全技術(shù)、承載網(wǎng)絡(luò)技術(shù)和無(wú)線(xiàn)公鑰基礎(chǔ)設(shè)施。其次分析其安全機(jī)制,討論了基于SMS、IVR、USSD、WAP和K-JAVA五種接入方式下支付系統(tǒng)的安全性及缺陷。最后在此基礎(chǔ)上提出兩個(gè)分別用于微支付和宏支付的新協(xié)議。它們都滿(mǎn)足無(wú)線(xiàn)網(wǎng)絡(luò)環(huán)境和移動(dòng)設(shè)備的特點(diǎn),解決了手持設(shè)備認(rèn)證、支付過(guò)程相互密鑰協(xié)商、傳輸數(shù)據(jù)保密性和完整性等問(wèn)題。前者采用共享密鑰技術(shù),實(shí)現(xiàn)了一次一密,具有較高的安全性和執(zhí)行效率,而且
3、無(wú)須可信第三方的參與,增加了實(shí)用性和易操作性。后者采用橢圓曲線(xiàn)密碼技術(shù),以較小密鑰量提供更大的安全性,所需帶寬明顯減少,而且還大大降低了用戶(hù)端的計(jì)算負(fù)擔(dān)和存儲(chǔ)要求,實(shí)現(xiàn)了快速高效的支付認(rèn)證和不可否認(rèn)性驗(yàn)證。關(guān)鍵詞:移動(dòng)支付安全機(jī)制認(rèn)證協(xié)議AbstractLowincostandwellinconvenience,theMobilePaymentreceivesmoreandmorewelcomefromtheconsumerandgraduallybecomesapopularwayofpayment.However,manyfactorsinthewi
4、relessenvironment,suchasthebandwidth,thesignalinterference,thenetworkinterception,theillegalusage,thevirus,eventhecharacteristicofthemobiledeviceitself,suchasthelowcomputingability,thelimitationofthememory,andsoon,hastobeconsidered,whichmakesthesecuritytechnologiesandthemechanism
5、soriginallyusedinthewiredpaymentnotsuitableforthemobilepayment.Therefore,itwillnotgrowuntilthesecuritytechnologicalhurdleshavebeenovercome.Atpresent,themobilepaymentusuallyoccursinthemicropaymentsituation,sotherequirementofsecurityisnotverypivotal,butwiththerapiddevelopmentofthee
6、lectroniccommerce,itwillgraduallybeappliedtothemacropaymentsituation,inevitablymuchhigherandstricterrequirementareneeded.Therefore,theresearchofanefficientsecuritymechanism,whichprovidesthedenialauthenticationability,hasagreattheoreticandpracticalvalue.Withtheseconsiderations,thi
7、sdissertationmakeseffortsandprovidesresultsasfollows:Firstly,atheoreticresearchisdonefortheMobilePaymentSystem(MPS),includingtheframe,industrychain,operationmode,functionmodule,securitytechnology,transportnetwork,andWPKIofMPS.Secondly,securitymechanismofMPSisstudied,includingthes
8、ecurityofAuthenticationprotocolandteleco