透過您的圖書館登入
IP:3.131.94.5
  • 學位論文

多用途憑證應用在公開鑰匙基礎建設之程式界面設計

The Application Interface Design for Multi-Purpose Certificates In the Public Key Infrastructure

指導教授 : 鄭鳳生
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


目前網路上的行為模式,其安全的問題讓人們相當的質疑,因此,早期的資訊安全、密碼學理論的研究開始被大眾所重視,安全的應用也就開始蓬勃發展。 目前網路應用程式大多透過網路傳遞帳號密碼據以辨識身份,卻因此造成安全上的漏洞,在Internet之開放環境下更形嚴重,而於PKI的架構下,憑證之應用得以解決傳輸安全與身份確認之問題。 未來在Internet的環境上,應用軟體將朝著以PKI為架構而設計,但是現在的程式開發者必須花較多的時間去學習如何設計以PKI為架構的應用程式,造成程式開發者程式設計上的困擾,所以本論文對上述的問題,做了以下的解決方案。 本論文設計了一個多用途憑證的應用程式界面讓不同廠商利用不同的程式語言,方便設計符合PKI架構的應用程式,其應用環境不但可應用在Internet 或Client-Server環境下更可結合現有的Web Server,其功能可用於管理憑證及處理安全通訊,更重要的是應用程式開發者可自行設計其使用者界面,增加設計彈性。

並列摘要


While the explosive advent of the Internet offers many promises for electronic commerce, it has also led to many concerns regarding security. Being an open network, the Internet is inherently difficult to secure. It is believed that cryptography can offer promising solutions to securing communications and transactions over the Internet. Hence, the great potential in the research of cryptography. Currently PIN numbers used to verify the identity of users are mostly transmitted over the network. This has opened security loopholes for hackers. In the Public Key Infrastructure (PKI) framework, digital certificate is used to offer secure key (PIN) exchange and user authentication. Secure applications built on PKI will be the future applications on the Internet. The main problem that is stopping developers from incorporating PKI security in their applications is the steep learning curve of understanding and applying the cryptography algorithms. This thesis paper addresses to this problem with a practical solution. This thesis has proposed a multi-purpose solution to ease developers from different background to design secure PKI-based applications under different development environment. It not only can be applied on the Internet or Client-Server based network, it can also be integrated into existing web servers. Among the many features offer such as certificate management and secure communication, the user interface can be customized for greater flexibility and convenience.

參考文獻


【4】 Secure Electronic ransaction(SET) Specification “Book 1.2.3”,http://www.mastercard.com/set/set.html,1997
【1】 政府憑證中心,憑證實作準則,www.pki.gov.tw,1998,2
【2】 電子商務專輯 「電腦與通訊」 第55期 12.5.1996
【3】 VeriFone Internet Commerce ,”vWallet Payment Application User’s Guid”, http://www.verifone.com,VPN 36011-01,1997
【5】 CyberCash,”CyberCash Wallet”, http://www.cybercash.com,1997

延伸閱讀