English  |  正體中文  |  简体中文  |  全文筆數/總筆數 : 64178/96951 (66%)
造訪人次 : 9307149      線上人數 : 1312
RC Version 7.0 © Powered By DSPACE, MIT. Enhanced by NTU Library & TKU Library IR team.
搜尋範圍 查詢小技巧:
  • 您可在西文檢索詞彙前後加上"雙引號",以獲取較精準的檢索結果
  • 若欲以作者姓名搜尋,建議至進階搜尋限定作者欄位,可獲得較完整資料
  • 進階搜尋
    請使用永久網址來引用或連結此文件: https://tkuir.lib.tku.edu.tw/dspace/handle/987654321/34117


    題名: 應用SAML安全斷言標示語言強化晶片卡交易機制之設計與實作
    其他題名: The design and implementation of using SAML to strengthen the IC card-based trade security
    作者: 張詠婷;Chang, Yung-ting
    貢獻者: 淡江大學資訊管理學系碩士班
    李鴻璋;Lee, Hung-chang
    關鍵詞: 雙因素認證;SET;SAML;EMV;Two-factor authentication
    日期: 2007
    上傳時間: 2010-01-11 04:56:10 (UTC+8)
    摘要: 隨著電子商務網站迅速發展,交易方式逐漸由實體交易轉為線上交易。由於傳統交易環境中的晶片卡付款方式已被消費者普遍接受,因此若能在網路環境中提供安全的晶片卡付款方式,必能提升消費者對使用線上晶片卡付款機制的接受度,所以VISA、MasterCard、Netscape與Microsoft等公司於1996年2月,制定了一套專為線上線用卡付款機制設計的安全電子交易規格SET(Secure Electronic Transaction)。

    儘管SET本身流程設計相當安全嚴謹,但卻無法抵抗近年來重要的資安漏洞—鍵盤側錄程式的惡意威脅,駭客可藉由側錄下來的使用者資訊進行重送攻擊,偽裝冒用消費者的名義做非法交易;且由於SET的使用必須負擔額外費用,並且必須安裝相關軟體如電子錢包,是以推廣成效不彰。因此本研究在使用SAML技術,依照現行EMV晶片卡規格,讓消費者所持有之晶片卡與收單銀行在進行交易確認前,實施雙因素認證(Two-Factor Authentication)(通行碼、憑證),以預防相關安全攻擊。讓線上交易不僅可以達到安全、便利的目地,更提供一個開放的新機制,以利推廣。
    As the rapid development of e-commerce, online transaction has become more popular than entity transactions. With traditional transactions, paying with IC card has been the method accepted by most consumers. If there is a safer payment method over the Internet, it will greatly enhance the acceptance of using IC card payment on-line. That is the main reason that VISA, MasterCard, Netscape, Microsoft and other companies have developed a specification, SET (Secure Electronic Transaction), for secure electronic transaction in February 1996.

    While SET itself is quite secure, it could not escape the recently popular security loophole, "the Keylogger". Through the replay attack, hackers can camouflage as consumers to do illegal transactions. Since usage of SET must pay additional costs, and related software such as electronic purse must be installed, the product was not very well accepted. In this research, I present a Two-Factor authentication system in accordance with the EMV specifications, and use SAML technology to ensure security of transactions between user and acquirer bank. With those technologies, it is not only safe and convenient to perform transaction on-line, but it is also easier to promote the new technology by offering a new mechanism.
    顯示於類別:[資訊管理學系暨研究所] 學位論文

    文件中的檔案:

    檔案 大小格式瀏覽次數
    0KbUnknown392檢視/開啟

    在機構典藏中所有的資料項目都受到原著作權保護.

    TAIR相關文章

    DSpace Software Copyright © 2002-2004  MIT &  Hewlett-Packard  /   Enhanced by   NTU Library & TKU Library IR teams. Copyright ©   - 回饋