智能与分布计算实验室
  基于SET的支付网关的研究与设计
姓名 袁姗姗
论文答辩日期 2006.05.08
论文提交日期 2006.05.09
论文级别 硕士
中文题名 基于SET的支付网关的研究与设计
英文题名 The Research and Design of A Payment Gateway Based on SET
导师1 卢正鼎
导师2
中文关键词 电子商务;安全电子商务标准协议;支付网关;支付安全
英文关键词 E-commerce;Secure Electronic Transactions Protocol;Payment gateway;Payment Secure
中文文摘 电子商务系统本身具有的实时性、便捷性等特性给它的应用带来了灵活的特点,但同时也引入了网上交易和网上支付的安全问题。安全支付网关是银行与互连网之间的安全枢纽,是电子商务中最重要的部分,由于SSL(Secure Sockets Layer)具有实现简单,处理交易便捷的特点,目前国内大部分使用基于SSL协议实现方式的支付网关。但由于其密钥位数不高,敏感信息以明文形式存在于服务器上,使得其安全性不够高。 在分析比较了目前的两种电子商务交易协议SSL和SET的基础上,结合银行内部金融网的特点,对如何保证电子商务环境下的支付安全,身份认证等技术进行了探讨和研究。基于SET的安全支付网关采用密钥密码技术,数字签名技术以及数字证书技术,成为银行金融网和互连网之间的一道安全屏障,完成了二者之间的数据通信和协议转换,使电子商务交易的安全性大大提高。 研究和设计基于SET的安全支付网关,首先明确了支付网关在整个电子商务体系中物理和逻辑的位置。由于SET是基于消息流的协议,在分析了SET所定义的支付方式的消息流、数据流和安全技术的基础上,归纳出支付网关应该完成的数据通信功能和应处理的交易各方的消息流,设计了安全支付网关的数据结构和消息集合,给出了支付网关应用的数据格式,建立了一个消息通信的模型并采用基于身份认证的证书体系和数字签名技术保证了参与交易的各方之间通讯消息的安全性,进而设计了基于SET的安全支付网关的系统模型,实现了支付网关保证电子商务交易安全性的功能。
英文文摘 The security payment gateway is the hinge between the bank and the internet, is the most inportant part of the E-Commerce. At present, most of the payment gateway are executed based on the SSL protocol, cause the simpleness and the convenient of the SSL protocol. But the shortcoming of the SSL protocol is that the secret-key of the encrpytion is not long enouth , and the sensitive imformation is exposive on the server of the web. So, we say that the payment gateway based on the SSL protocol is not security enough. The security payment gateway based on the SET protocol uses the secret-key encrpytion, numeric idiogragh and the numeric certification, which provide the enough security. The security payment gateway becomes the security barrier between the Internet and the finance net. At the same time, the payment gateway transforms the protocol between them, and does the communication. So, we provide the payment on-line. Researching and designing the payment gateway based on the SET, we must know the physical and logistic position of the payment gateway in the E-commerce system, and the function of it. SET is the protocol that based on the message-flow, this paper analyse the message-flow and the data-flow of the SET payment, design the data-frame and message-collection of the security payment gateway based on the SET protocol, and the encrytion realization.We make the detailed analysis and design about the message-flow of the payment gateway based on the SET, in succession, advance the prototype system of the payment gateway, realize the security-payment based on the SET.