hsm (hardware security module).pdf

Upload: alessandro-jose-segura-de-oliveira

Post on 14-Jan-2016

137 views

Category:

Documents


5 download

TRANSCRIPT

  • HSM (Hardware Security Module)

  • 2007/03//16 2 FINANCIAL INFORMATION SERVICE CO.,LTD.

    HSM

    HSM

    HSM

  • HSM

  • 2007/03//16 4 FINANCIAL INFORMATION SERVICE CO.,LTD.

    (Integrity)

    (Confidentiality)

    (Authentication)

    (Non-repudiation)

  • 2007/03//16 5 FINANCIAL INFORMATION SERVICE CO.,LTD.

  • 2007/03//16 6 FINANCIAL INFORMATION SERVICE CO.,LTD.

    ()

    () ()

    (Diversify)

  • 2007/03//16 7 FINANCIAL INFORMATION SERVICE CO.,LTD.

    ()

    () (Personal Identify Number, PIN)PIN Block

    (PIN Protection Key)PIN Block

    953

  • 2007/03//16 8 FINANCIAL INFORMATION SERVICE CO.,LTD.

    ()(Message Authentication Code, MAC)

    (Key Sync Check Item) ()

  • 2007/03//16 9 FINANCIAL INFORMATION SERVICE CO.,LTD.

    ()

    FISCATM

  • 2007/03//16 10 FINANCIAL INFORMATION SERVICE CO.,LTD.

    ()K1 K2 K3

    E D EInput Output

    Triple-DES Encryption(K1 = K3) K2, Key Length 112 bitsK1 K2 K3, Key Length 168 bits

    K1

    E D EInput Output

    EncryptionK1, Key Length 56 bits

  • 2007/03//16 11 FINANCIAL INFORMATION SERVICE CO.,LTD.

    ()

    () Card Verification Value (CVV)Card Verification

    Code (CVC) () (Card Verification Key, CVK)Service Code3

  • 2007/03//16 12 FINANCIAL INFORMATION SERVICE CO.,LTD.

    ()()

    PIN Verification Value (PVV) (PIN Verification Key, PVK)4

    ()

  • 2007/03//16 13 FINANCIAL INFORMATION SERVICE CO.,LTD.

    ()()

    Authorization Request Cryptogram (ARQC)

    (Diversify)

  • 2007/03//16 14 FINANCIAL INFORMATION SERVICE CO.,LTD.

    ()UK-AC(L) = 3DES(MK-AC, 9937000001312000)

    = 2F9752D23A2B708BUK-AC(R) = 3DES(MK-AC, ~9937000001312000)

    = 3DES(MK-AC, 66C8FFFFFECEDFFF)= F4245DD9C25E8C89

    OTmp = The last block of DES(UK-AC(L), 000000000128000000000000015880C00010000901071201409F1971701C0001)

    = C7F4200B4EA70AAFARQC = 3DES(UK-AC, OTmp 7B03A08000000000)

    = 3DES(UK-AC, BCF7808B4EA70AAF)= 2CAAEF006841ABED

    MK-AC:Issuer Master Key-Authentication Cryptogram

    UK-AC:User Key-Authentication Cryptogram

  • 2007/03//16 15 FINANCIAL INFORMATION SERVICE CO.,LTD.

    Financial Electronic Data Interchange (FEDI)

    ()

  • 2007/03//16 16 FINANCIAL INFORMATION SERVICE CO.,LTD.

    ()

    ()

    ()

    ()

    ()

  • 2007/03//16 17 FINANCIAL INFORMATION SERVICE CO.,LTD.

    ()

    EncryptDecrypt

    Public KeyPrivate Key

    hash Compare ?

    hash

  • HSM

  • 2007/03//16 19 FINANCIAL INFORMATION SERVICE CO.,LTD.

    HSM

  • 2007/03//16 20 FINANCIAL INFORMATION SERVICE CO.,LTD.

    ()

    (HSM)

  • 2007/03//16 21 FINANCIAL INFORMATION SERVICE CO.,LTD.

    () HSM

    HSM

    HSM HSM

  • 2007/03//16 22 FINANCIAL INFORMATION SERVICE CO.,LTD.

    HSM

    82

    83

    92 (CD/ATM)

  • 2007/03//16 23 FINANCIAL INFORMATION SERVICE CO.,LTD.

    HSM()

    (Master Key)

  • 2007/03//16 24 FINANCIAL INFORMATION SERVICE CO.,LTD.

    HSM()()

  • HSM

  • 2007/03//16 26 FINANCIAL INFORMATION SERVICE CO.,LTD.

    People

    Process

    Technology

  • 2007/03//16 27 FINANCIAL INFORMATION SERVICE CO.,LTD.

  • 2007/03//16 28 FINANCIAL INFORMATION SERVICE CO.,LTD.

    ()

  • 2007/03//16 29 FINANCIAL INFORMATION SERVICE CO.,LTD.

    ()

    (Dual Control)

  • 2007/03//16 30 FINANCIAL INFORMATION SERVICE CO.,LTD.

    ()()

    ()

  • 2007/03//16 31 FINANCIAL INFORMATION SERVICE CO.,LTD.

    (2)

    HSM (Hardware Security Module) HSM()()()()()()()()()HSMHSMHSMHSM()HSM()HSM()()