• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

Computer Engineering & Science

Previous Articles     Next Articles

Research on the loophole of offline dynamic data
authentication in financial IC card specification

DU Lei,LI Zeng-ju,PENG Qian,SHI Ru-hui,ZHANG Ce   

  1. (Beijing UnionPay Card Technology Ltd.,Beijing 100070,China)
  • Received:2015-06-25 Revised:2015-10-12 Online:2016-10-25 Published:2016-10-25

Abstract:

 The research focuses on the offline data authentication mechanism in part 5, 12, 13, 14 of “China Financial Integrated Circuit Card Specifications” (JR/T 0025, referred to as “PBOC”), and evaluates its ability against side channel attacks, differential fault analysis and dictionary attacks. We find out that the offline data authentication has a flaw against financial IC card forgery and experiments on the financial cards issued by the bank verify our finding. Finally we propose several countermeasures against these attacks.

Key words: PBOC 3.0, offline data authentication, dictionary attack, entropy