• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2013, Vol. 35 ›› Issue (6): 72-77.

• 论文 • 上一篇    下一篇

网上银行安全支付问题研究

张丽娜1,阎文斌2   

  1. (1.西安科技大学计算机科学与技术学院,陕西 西安 710054;2.北京邮电大学软件学院,北京 100876)
  • 收稿日期:2012-10-22 修回日期:2012-12-21 出版日期:2013-06-25 发布日期:2013-06-25
  • 基金资助:

    西安科技大学科研培育基金资助项目(A5150531)

Research on secure payment in online banking          

ZHANG Lina1,YAN Wenbin2   

  1. (1.School of Computer Science and Technology,Xi’an University of Science and Technology,Xi’an 710054;
    2.School of Software Engineering,Beijing University of Posts and Telecommunications,Beijing 100876,China)
  • Received:2012-10-22 Revised:2012-12-21 Online:2013-06-25 Published:2013-06-25

摘要:

随着网上银行用户数量和交易金额的日益增多,网上银行系统成为很多攻击者的首选目标,其安全问题也成为很多用户选择网上银行时的主要考虑因素之一,这在一定程度上阻碍了网上银行业务的发展。在线支付的安全问题已成为各大银行和研究者的关注焦点。根据在线支付系统的一般流程,对客户端在登录和请求支付时可能面临的各类攻击模型进行讨论,根据攻击手段给出其安全性分析和具体的解决方案,重点分析了攻击者篡改签名数据的方法和流程,给出了相应的设计方案和防范措施。

关键词: 网上银行, 公钥基础设施, 加密服务提供者, 签名, 智能卡

Abstract:

With the increase of the number of users and the total amount of transactions of online banking, it has become the preferred target of some attackers. The security issue has become one of the main considerations of users. To some extent, this has hindered the development of online banking. The related security has become one of the focused issues of the most banks and researchers. Based on analyzing the basic processes of online payment and the mode of attack, we discussed its security and proposed related prevention techniques. The processes of tampering with the signature data were analyzed, then corresponding system model and design strategies were discussed in detail.

Key words: online banking;public key infrastructure;cryptographic service providers;signature;smart card