2023年U盾技术问题解决方案.docx
《2023年U盾技术问题解决方案.docx》由会员分享,可在线阅读,更多相关《2023年U盾技术问题解决方案.docx(8页珍藏版)》请在淘文阁 - 分享文档赚钱的网站上搜索。
1、2023年U盾技术问题解决方案 From perspective of banks risk management of online payment 1 对于当前中国网上银行系统,加强网银用户的身份认证管理,防止用户资料的泄露,是减少由于U盾自身缺陷导致的网上银行安全隐患的有效措施。 According to the current Chinese online banking system, strengthening online banking user authentication management, and preventing users from data leaks ca
2、n be effective measures that largely reduce online banking security risks as a result of the defects of USBKEY.Chinese major commercial banks should strengthen the application of the technologies of two or more factors authentication.Commercial banks can combine the technology of the dynamic paword
3、card and other authentication certificates with USBKEY. 2 建立并使用入侵检测系统(IDS),以防范USBKEY出现的缺陷风险。 IDS可以对用户使用USBKEY进行网络支付的数据包起到监视作用,但并不延误其传送速度。可以将用于检测和分析的检测引擎分布在网络敏感部位,如内部网络的入口处、担负重要任务或处理重要数据的服务器周围。 Establish and make use of intrusion detection systems (IDS) to prevent the risk of defects occurring by USB
4、KEY.IDS can monitor a packet that is transmitted by a USBKEY user who is intending to pay online, but not delay the speed of data transmiion. From perspective of the technologies for USBKEY 1 依据情况改造现有的USB Key,增加输入键,使其PIN码可以在USB Key上输入,这样就不会被电脑上的木马拦截。 According to the vulnerabilities that existing in
5、 the USBKEY, transform the USBKEYS by increasing input keys, so that PIN code can be entered on the USBKEY.Then, information will not be intercepted Trojan on the computer. 2. 条件允许情况下,可以把USBKEY和动态密码锁的加密方式结合在一起。 智能卡芯片和读卡器结合在一起的USB Key,带有智能卡芯片的USB Key可以通过内置的智能卡芯片在Key内部硬件实现DES/3DES、RSA加解密运算,并支持Key内生成RS
6、A密钥对,杜绝了密钥在客户端内存中出现的可能性,可以大大提高安全性。 If conditions permitting, we can combine encryption methods of the USBKEY and dynamic encryption paword lock together.A version of USBKEY that combines the smart card and reader together can do decrypting operation of Des、3DES and RSA in the internal hardware chip
7、by the built-in smart card.This USBKEY supports the generation of RSA Private-key Pairs.This will reduce and prevent the poibility that the Private-key Pairs stay in the memory of client.And then greatly enhance security. 3.可以针对现有USB Key的键盘输入PIN码的漏洞,可以使用生物技术(例如个人指纹)来替换键盘录入PIN码。 也就是说,交易时候接入USB Key,我们
8、不需要再到键盘录入PIN码来验证身份。我们只需要在USB Key的设备上按一下指纹,就能自动验证个人身份。这种身份验证机制带来的安全性和实用性是一种跨时代的提高。 用户不可能再忘记密码了,只需要验证指纹即可。指纹的验证实在外部设备上进行的,电脑即使被黑客完全控制也无法截取到用户的指纹,从而保证了PIN码的唯一性和安全性。 According to the loopholes of the keyboard method of inputting PIN of USBKEY, you can use bio-technology (such as personal fingerprint) to
9、 replace the method of inputting PIN.In other words, when for the acce of USBKEY, we do not need to enter pin code by the keyboard for authentication.We only need a pre on the USBKEY by a finger for the fingerprints, and then the system can automatically verify our individual IDs.This authentication
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- 2023 技术 问题解决 方案
限制150内