透過您的圖書館登入
IP:3.133.121.160
  • 學位論文

應用SAML安全斷言標示語言強化晶片卡交易機制之設計與實作

The Design and Implementation of Using SAML to Strengthen the IC Card-Based Trade Security

指導教授 : 李鴻璋

摘要


隨著電子商務網站迅速發展,交易方式逐漸由實體交易轉為線上交易。由於傳統交易環境中的晶片卡付款方式已被消費者普遍接受,因此若能在網路環境中提供安全的晶片卡付款方式,必能提升消費者對使用線上晶片卡付款機制的接受度,所以VISA、MasterCard、Netscape與Microsoft等公司於1996年2月,制定了一套專為線上線用卡付款機制設計的安全電子交易規格SET(Secure Electronic Transaction)。 儘管SET本身流程設計相當安全嚴謹,但卻無法抵抗近年來重要的資安漏洞—鍵盤側錄程式的惡意威脅,駭客可藉由側錄下來的使用者資訊進行重送攻擊,偽裝冒用消費者的名義做非法交易;且由於SET的使用必須負擔額外費用,並且必須安裝相關軟體如電子錢包,是以推廣成效不彰。因此本研究在使用SAML技術,依照現行EMV晶片卡規格,讓消費者所持有之晶片卡與收單銀行在進行交易確認前,實施雙因素認證(Two-Factor Authentication)(通行碼、憑證),以預防相關安全攻擊。讓線上交易不僅可以達到安全、便利的目地,更提供一個開放的新機制,以利推廣。

關鍵字

SET SAML EMV 雙因素認證

並列摘要


As the rapid development of e-commerce, online transaction has become more popular than entity transactions. With traditional transactions, paying with IC card has been the method accepted by most consumers. If there is a safer payment method over the Internet, it will greatly enhance the acceptance of using IC card payment on-line. That is the main reason that VISA, MasterCard, Netscape, Microsoft and other companies have developed a specification, SET (Secure Electronic Transaction), for secure electronic transaction in February 1996. While SET itself is quite secure, it could not escape the recently popular security loophole, "the Keylogger". Through the replay attack, hackers can camouflage as consumers to do illegal transactions. Since usage of SET must pay additional costs, and related software such as electronic purse must be installed, the product was not very well accepted. In this research, I present a Two-Factor authentication system in accordance with the EMV specifications, and use SAML technology to ensure security of transactions between user and acquirer bank. With those technologies, it is not only safe and convenient to perform transaction on-line, but it is also easier to promote the new technology by offering a new mechanism.

並列關鍵字

SET SAML EMV Two-factor authentication

參考文獻


[8]. 蔡緣,「國際商業信用狀實務」,華泰文化事業股份有限公司,2001年8月
[12]. Silva, F.O., Pacheco, J.A.A. and Rosa, P.F., “A Web service authentication control system based on SRP and SAML,” Proceedings of the IEEE International Conference on Web Services (ICWS’05), 2005, pp. 11-15.
[13]. Taekyoung Kwon., “Impersonation attacks on software-only two-factor authentication schemes,” IEEE Communications Letters, Vol. 6, No. 8, 2004, pp.358-360.
[14]. Ruschlikon and Switzerland, IBM Zurich Res. Lab., “Security analysis of the SAML single sign-on browser/artifact profile,” Proceedings of the 19th Annual Computer Security Applications Conference (ACSAC 2003), 2003, pp.298-307.
[15]. Jun Wang, Del Vecchio, D., and Humphrey, M., “Extending the security assertion markup language to support delegation for Web services and grid services,” Proceedings of the IEEE International Conference on Web Services (ICWS’05), Vol. 6, 2005, pp. 67-74.

被引用紀錄


張哲綸(2009)。以隱匿信用卡卡號為基礎之改良式電子付款機制〔碩士論文,亞洲大學〕。華藝線上圖書館。https://www.airitilibrary.com/Article/Detail?DocID=U0118-1511201215461481

延伸閱讀