摘要
Non-SET支付系统是我国主流的电子商务支付系统,MD5等散列算法被破译,给支付系统施加了安全隐患。提出了一种安全增强的Non-SET支付系统设计方案,以基于SSL和SET相融合的支付协议为中心,阐述安全增强的主要关键技术:嵌入优化实现的AES算法到SSL协议中、基于该AES算法构建安全散列算法并将它嵌入到SSL协议中、设计实现安全代理和微型CA系统。
The Non-SET payment systems are very popular payment systems for electronic commerce. As the hash functions such as MD5 are decrypted, which brings many risks and threats to those payment systems. The security improvement' s solution to the Non- SET payment systems is introduced, which centralizes fusion-based payment protocol for secure electronics transactions (SET) protocol and secure socket layer (SSL) protocol, the main key technologies of the security improvement is studied such as integration optimized advanced encryption standard (AES) into the SSL protocol, building the secure hash function based on the AES and its integration into the SSL protocol, and design and implementation of the security proxy and the micro authority certificate (CA).
出处
《计算机工程与设计》
CSCD
北大核心
2008年第19期4963-4966,5086,共5页
Computer Engineering and Design
基金
重庆市教委科研基金项目(KJ050508)
重庆市自然科学基金项目(CSTC2006BB2369)
国家社会科学基金项目(07XFX018)