Skip to main content
QUICK REVIEW

[论文解读] The Algorithm Analysis of E-Commerce Security Issues for Online Payment Transaction System in Banking Technology

Raju Barskar, Anjana Jayant Deen|arXiv (Cornell University)|May 24, 2010
Internet Traffic Analysis and Secure E-voting参考文献 1被引用 12
一句话总结

本文分析了用于保护电子商务银行系统在线支付交易的密码算法,提出了一套技术与管理解决方案的协调框架,以应对不断演变的安全威胁。它强调算法选择与集成对于减轻基于互联网的金融交易中的漏洞至关重要。

ABSTRACT

E-Commerce offers the banking industry great opportunity, but also creates a set of new risks and vulnerability such as security threats. Information security, therefore, is an essential management and technical requirement for any efficient and effective Payment transaction activities over the internet. Still, its definition is a complex endeavor due to the constant technological and business change and requires a coordinated match of algorithm and technical solutions. Ecommerce is not appropriate to all business transactions and, within e-commerce there is no one technology that can or should be appropriate to all requirements. E-commerce is not a new phenomenon; electronic markets, electronic data interchange and customer e-commerce. The use of electronic data interchanges as a universal and non-proprietary way of doing business. Through the electronic transaction the security is the most important phenomena to enhance the banking transaction security via payment transaction.

研究动机与目标

  • 应对由于技术与业务发展而日益增长的电子商务银行系统安全风险。
  • 识别由于算法与技术协调不足而导致的在线支付交易系统中的漏洞。
  • 提出一个框架,将密码算法与技术及管理要求相协调,以实现安全的电子支付处理。
  • 评估现有技术对多样化电子商务交易需求的适用性,拒绝采用‘一刀切’的方法。
  • 通过将算法解决方案与特定交易安全需求相匹配,增强系统韧性。

提出的方法

  • 分析现有的电子商务和电子数据交换(EDI)系统,作为安全交易设计的基础模型。
  • 根据其在保护在线银行交易中的适用性,评估密码算法。
  • 提出一种协调方法,将技术解决方案(例如加密、认证)与管理实践相结合。
  • 强调在电子交易协议中采用非专有、通用标准的必要性,以确保互操作性与安全性。
  • 聚焦于算法选择作为系统设计的核心组成部分,根据特定风险概况进行定制。
  • 使用IEEE出版标准并通过期刊投稿进行实证验证,以确保方法论的严谨性。

实验结果

研究问题

  • RQ1哪些密码算法在保护银行系统中的在线支付交易方面最为有效?
  • RQ2如何协调技术与管理解决方案以增强电子商务交易的安全性?
  • RQ3在保护多样化电子商务支付系统时,‘一刀切’技术方法存在哪些局限性?
  • RQ4不断演变的业务与技术变化如何影响电子商务中信息安全的定义与实施?
  • RQ5非专有标准(如EDI)在提升电子支付系统安全性和可靠性方面发挥什么作用?

主要发现

  • 由于需求和威胁环境的多样性,没有单一技术或算法能够保护所有电子商务支付交易。
  • 有效的安全需要根据特定交易类型量身定制算法与技术解决方案的协调匹配。
  • 密码算法必须基于其对不断演变威胁的抗御能力以及与系统架构的兼容性来选择。
  • 采用通用的非专有标准(如EDI)可增强电子交易的安全性与互操作性。
  • 由于技术与商业模式的持续演变,信息安全仍然是一个复杂挑战。
  • 本文提出的框架为算法选择与系统集成提供了一套结构化方法,从而提升了整体交易安全性。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。