跳到主要內容

臺灣博碩士論文加值系統

(216.73.217.177) 您好!臺灣時間:2026/08/12 23:57
字體大小: 字級放大   字級縮小   預設字形  
回查詢結果 :::

詳目顯示

: 
twitterline
研究生:孟子元
研究生(外文):Meng Zih-Yuan
論文名稱:以橢圓曲線密碼學為基礎之行動商務安全支付協定
論文名稱(外文):A Secure Payment Protocol For Mobile Commerce Based On ECC
指導教授:陳昱仁陳昱仁引用關係
指導教授(外文):Chen Yuh-Ren
學位類別:碩士
校院名稱:長庚大學
系所名稱:資訊管理研究所
學門:電算機學門
學類:電算機一般學類
論文種類:學術論文
論文出版年:2004
畢業學年度:92
語文別:中文
論文頁數:88
中文關鍵詞:行動商務無線公開金鑰基礎建設橢圓曲線密碼學代理簽章安全支付協定
外文關鍵詞:M-CommerceWireless Public Key InfrastructureElliptic Curve CryptographyProxy SignatureSecure Mobile Payment Protocol
相關次數:
  • 被引用被引用:10
  • 點閱點閱:579
  • 評分評分:
  • 下載下載:114
  • 收藏至我的研究室書目清單書目收藏:10
隨著網際網路的普及,電子商務因而蓬勃發展。繼之,網路由有線邁向無線化,又催生了行動商務的誕生。目前,行動商務儼然已成為電子商務後的最新趨勢,愈來愈多的網際網路所能提供的服務,都被移植至無線環境上,如:網路花店、火車時刻查詢及訂票、股市查詢等。由於行動商務是基於原有電子商務架構下所產生的典範轉移,因此一樣繼承了電子商務“四流”─資訊流、商流、金流、物流中的安全問題,尤其在無線環境下,「資訊流」與「金流」最為民眾所擔心,因為一旦遭受惡意的第三者攻擊,此二者對於消費者的影響最為廣大。
無線網路有著高度的自由度及機動性,但也因為突破有線網路的地理限制,使得在資料傳輸時,若面對未經授權的存取及攻擊會顯的較為脆弱。近代密碼學自Diffie與Hellman提出公開金鑰密碼系統為始,迄今已將近三十年,其中陸續的解決了有線網路上的安全問題。WAP Forum有鑑於此,試圖將各種公開金鑰密碼系統、金鑰交換協定及數位簽章技術應用在無線網路上,因此「無線公開金鑰基礎建設」於西元2000年誕生。
本研究以探討橢圓曲線密碼學為起點,結合身份鑑別及代理簽章,提出一個植基於「無線公開金鑰基礎建設」的安全支付協定。在研究結果中可發現,本架構可達到效率性、安全性及便利性,冀望對於行動商務的實務做法上,能提出一個不同的解決方案。
With the popularization of the Internet, Electronic Commerce (E-Commerce) grows vigorously. After that, the network strides forward to wireless, and it promotes the development of Mobile Commerce (M-Commerce). At present, the M-Commerce has already become the newest trend after E-Commerce. More and more services on Internet have been transferred to wireless environment; for instance, on-line floristic shop, inquiry of train schedule and ticket booking, and inquiry of stock quotes, etc. Because M-Commerce is the paradigm shift based on the structure of E-Commerce, it inherited the security issues about the four flows, including the information flow, business flow, cash flow and distribution flow, of E-Commerce. Especially under the wireless environment, most people worry about the information flow and cash flow. It is because that when attacked by the hacker, the influence of these two flows on consumers is the most serious.
The wireless network has the characteristics of freedom and mobility. Because of breaking through the geography limit of wired network, it is weaker when the data were transmitted under unauthorized access and attack. The development of modern cryptography is nearly 30 years since Diffie and Hellman proposed "Diffie-Hellman Key Agreement Protocol", and the security problems on wired network are solved .in succession. WAP Forum, in view of this, attempted to apply public-key cryptographic systems, encrypted key exchange protocols and digital signature techniques on the wireless network. Therefore, "Wireless Public Key Infrastructure (WPKI)" was born in A.D. 2000.
This research is based on Elliptic Curve Cryptography (ECC), and combines authentication mechanism and proxy signature scheme to propose a secure mobile payment protocol based on WPKI. We show that the proposed protocol is efficient, secure and convenient, and we hope that this research can put forward a different solution for M-Commerce.
誌謝 I
摘要 II
ABSTRACT III
目次 V
圖目次 VII
表目次 IX
第一章 緒論 1
1.1 研究背景與動機 1
1.2 研究目的 4
1.3 研究流程與方法 6
1.4 章節概要 7
第二章 文獻探討 9
2.1 電子支付系統簡介 9
2.1.1 Paybox 9
2.1.2 PayPal 10
2.1.3 PayWare mAccess 11
2.1.4 Twister X.Pay 12
2.1.5 綜合分析 14
2.2 無線公開金鑰基礎建設 17
2.3 密碼驗證 21
2.4 代理簽章 23
2.5 橢圓曲線密碼學 25
2.5.1 實數系上的橢圓曲線 27
2.5.2 橢圓曲線的加法運算 28
2.5.3 橢圓曲線的乘法運算 30
2.5.4 有限域上的橢圓曲線 32
2.5.5 橢圓曲線的加解密 35
2.6 本章結論 35
第三章 安全支付協定設計 37
3.1 協定的基本概念 37
3.2 系統架構 37
3.3 系統參數定義 39
3.3.1 系統建置階段 39
3.3.2 交易階段 41
3.4 購物清單及請款單設計 41
3.5 系統流程 43
3.6 本章結論 49
第四章 系統分析與實作 51
4.1 系統分析 51
4.2 系統實作 55
4.2.1 系統實作環境 55
4.2.2 系統功能實作 57
4.3 本章總結 70
第五章 安全性與效率分析 71
5.1 安全性分析 71
5.2 效率分析 74
5.2.1 時間複雜度分析 74
5.2.2 通訊傳輸量 76
5.2.3 交易完成時間 79
5.3 本章結論 79
第六章 結論與未來發展 80
6.1 結論與研究貢獻 80
6.2 未來發展 82
參考文獻 85
英文部份(以字母順序排序):
[1] A Guide To ECC’s Library, Institute for Applied Information Processing and Communication, June 18.2003, pp.4-5
[2] Aleksandar Jurisic, Alfred J. Menezes, Elliptic Curves and Cryptography, http://www.certicom.com , 1997, pp.10-11.
[3] Byoungcheon Lee, Heesun Kim, and Kwangjo Kim, Strong Proxy Signature and its Applications, SCIS''2001, 11B-1, Osio, Japan , Jan. 23-26, 2001, pp.603-608.
[4] Certicom Corp., “SEC 1: elliptic curve cryptography,” Standards for Efficient Cryptography Group, September 2000. (URL:http://www.secg.org/).
[5] Certicom, ECC Tutorial, http://www.certicom.com/index.php?action=ecc_tutorial,home .
[6] Certicom, Wireless Public-Key Infrastructure, http://www.certicom.com/pdfs/whitepapers/Trustpoint_Wireless_PKI.pdf , 2001, pp.7-8.
[7] Certicom, Wireless Public-Key Infrastructure, http://www.certicom.com/pdfs/whitepapers/Trustpoint_Wireless_PKI.pdf , 2001, pp.4-5.
[8] Chablis, Market Analysis of Digital Payment Systems, http://chablis.informatik.tu-muenchen.de/MStudy/x-a-marketpay.html .
[9] Digital Equipment Corp: http://www.digital.com .
[10] Dr. Ricarda Weber, ”Security / Electronic Commerce”, SIEMENS, March 2001.
[11] E.P.E. Cuijpers, A design for a safe Internet communication channel with the help of smartcards, http://www.iscit.surfnet.nl/team/Erik/masterth/authenti.htm, 1997.
[12] Grady Booch, James Rumbaugh, Ivar Jacobson , The Unified Modeling Language User Guide, 1998, 1st edition, Addison-Wesley Pub Co.
[13] Gwoboa Horng, Chi-Hwai Shi, Shu-Chuan Kuo and Wen-Yi Chiu, A New Proxy Signature Scheme, ISC2002, Taichung, Taiwan, 2002, pp.63-68.
[14] INITECH Corp: http://www.initech.com
[15] Internet RFC/STD/FYI/BCP Archives, The MD5 Message-Digest Algorithm, http://www.faqs.org/rfcs/rfc1321.html .
[16] J.Pollard, “Monte Carlo methods for index computation modP”, Mathematics of Computation, 32, pp 918-924, 1978.
[17] MAMBO, Masahiro, USUDA, Keisuke and OKAMOTO, Proxy Signatures: Delegation of the Power to Sign Message, IEICE Trans. Fundamentals, 1996, pp. 1338-1354.
[18] Siau, K., Ee-Peng Lim and Zixing Shen, Mobile Commerce: Promises, Challenges, and Research Agenda, Journal of Database Management, July-Sept 2001, pp 4-13.
[19] Steven M. Bellovin and Michael Merritt, Encrypted Key Exchange: Password-Based Protocols Secure Against Dictionary Attacks, in Proc. IEEE Computer Society Symposium on Research in Security and Privacy, May 1992, pp.72--84.
[20] Steven M. Bellovin, Michael Merritt, Augmented Encrypted Key Exchange, in Proceedings of the First ACM Conference on Computer and Communications Security , November 1993, pp.244-250.
[21] Tarasewich P., R. C. Nickerson and M. Warkentin, “Issues in Mobile E-Commerce”, Communications of the Association for Information System, 2002, Vol. 8, pp.41-64.
[22] W. Diffie, P.C. van Oorschot, and M.J. Wiener, Authentication and authenticated key exchange, Designs, Codes, and Cryptography, Vol. 2, No. 2, 1992, pp. 107-125.
[23] WAP Forum, Wireless Application Protocol Public Key Infrastructure Definition, March 2000, pp.12-14.
[24] William Stallings, Cryptography and Network Security: Principles and Practices, 2002, Third Edition, New Jersey, Prentice Hall, pp.297-308.
[25] X.Lai and J.Massey, “A Proposal for a New Block Encryption Standard”, in Procceeding of EUROCRYPT ‘90(Springer-Verlag, Berlin, 1991), pp.389-404.
中文部份(以筆劃排序):
[26] 台灣國際電子商務中心─EC研究報告,解析PayPal的成功模式, 2002年1月,http://www.nii.org.tw/cnt/info/Report/20020102.htm。
[27] 吳宗成、黃孝慈、許建隆,具金鑰交換的群體導向鑑別機制之遞迴式協定設訂,中華民國資訊協會通訊,第二卷第三期,第21至30頁,1999年9月。
[28] 李秋薇,「管窺行動電子商務付款機制之進展」,工研院IEK中心產業評析報告,民國89年12月。
[29] 曹偉駿、周智禾,「一個有效率且安全之訊息可回復公正盲簽章機制」,第十三屆全國資訊安全會議,2003年8月,第54至61頁。
[30] 黃呈豐,「行動化企業之經營模式與應用策略」,國立台灣大學商學研究所碩士論文,民國91 年6 月。
[31] 楊子德,「連接器下游應用市場─手機、數位相機、遊戲機」,工研院IEK中心產業評析報告,民國93年2月。
[32] 賴柏諭,WAP網站開發指南,民國89年,初版,台北,文魁出版社,第2至6頁。
QRCODE
 
 
 
 
 
                                                                                                                                                                                                                                                                                                                                                                                                               
第一頁 上一頁 下一頁 最後一頁 top