ATM USER AUTHENTICATION BY LINKING RANDOMLY-GENERATED AUTHENTICATION SECRET WITH PERSONALIZED SECRET
碩士 === 長庚大學 === 資訊管理研究所 === 94 === Smart card, also known as Integrated-Circuit card, has replaced magnetic stripe card as a means of cardholder authorization, and it has been used for accessing bank accounts via Automatic Teller Machine (ATM). This master thesis presents a design to strengthen the...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | zh-TW |
Published: |
2006
|
Online Access: | http://ndltd.ncl.edu.tw/handle/74465959148116216215 |
id |
ndltd-TW-094CGU00396012 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-094CGU003960122015-10-13T10:37:49Z http://ndltd.ncl.edu.tw/handle/74465959148116216215 ATM USER AUTHENTICATION BY LINKING RANDOMLY-GENERATED AUTHENTICATION SECRET WITH PERSONALIZED SECRET 藉由隨機產生的認證秘密與個人化秘密之ATM持卡人身分認證方法 Ya-Ling CHIU 邱雅翎 碩士 長庚大學 資訊管理研究所 94 Smart card, also known as Integrated-Circuit card, has replaced magnetic stripe card as a means of cardholder authorization, and it has been used for accessing bank accounts via Automatic Teller Machine (ATM). This master thesis presents a design to strengthen the smart card system security without changing the system infrastructure. The design is based on a split-secret theory which separates the secret identifier stored in the smart card into two parts. One of these two parts is a passcode chosen by the cardholder, and the other is used to replace the original secret identifier as the stored secret. The original secret identifier, when necessary, can be recovered from these two parts. The passcode entry is verified by comparing the recovered value against a stored verifier. This verifier is a derivative of the original secret identifier processed through, for instance, a double-hash function. Since neither the hashed values nor similar derivatives of the passcode are stored, this design strengthens the passcode protection. The security of the system is also strengthened because the smart card now stores only half of the information of the secret identifier. Jing-Jang HWANG 黃景彰 2006 學位論文 ; thesis 82 zh-TW |
collection |
NDLTD |
language |
zh-TW |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 長庚大學 === 資訊管理研究所 === 94 === Smart card, also known as Integrated-Circuit card, has replaced magnetic stripe card as a means of cardholder authorization, and it has been used for accessing bank accounts via Automatic Teller Machine (ATM). This master thesis presents a design to strengthen the smart card system security without changing the system infrastructure.
The design is based on a split-secret theory which separates the secret identifier stored in the smart card into two parts. One of these two parts is a passcode chosen by the cardholder, and the other is used to replace the original secret identifier as the stored secret. The original secret identifier, when necessary, can be recovered from these two parts. The passcode entry is verified by comparing the recovered value against a stored verifier. This verifier is a derivative of the original secret identifier processed through, for instance, a double-hash function.
Since neither the hashed values nor similar derivatives of the passcode are stored, this design strengthens the passcode protection. The security of the system is also strengthened because the smart card now stores only half of the information of the secret identifier.
|
author2 |
Jing-Jang HWANG |
author_facet |
Jing-Jang HWANG Ya-Ling CHIU 邱雅翎 |
author |
Ya-Ling CHIU 邱雅翎 |
spellingShingle |
Ya-Ling CHIU 邱雅翎 ATM USER AUTHENTICATION BY LINKING RANDOMLY-GENERATED AUTHENTICATION SECRET WITH PERSONALIZED SECRET |
author_sort |
Ya-Ling CHIU |
title |
ATM USER AUTHENTICATION BY LINKING RANDOMLY-GENERATED AUTHENTICATION SECRET WITH PERSONALIZED SECRET |
title_short |
ATM USER AUTHENTICATION BY LINKING RANDOMLY-GENERATED AUTHENTICATION SECRET WITH PERSONALIZED SECRET |
title_full |
ATM USER AUTHENTICATION BY LINKING RANDOMLY-GENERATED AUTHENTICATION SECRET WITH PERSONALIZED SECRET |
title_fullStr |
ATM USER AUTHENTICATION BY LINKING RANDOMLY-GENERATED AUTHENTICATION SECRET WITH PERSONALIZED SECRET |
title_full_unstemmed |
ATM USER AUTHENTICATION BY LINKING RANDOMLY-GENERATED AUTHENTICATION SECRET WITH PERSONALIZED SECRET |
title_sort |
atm user authentication by linking randomly-generated authentication secret with personalized secret |
publishDate |
2006 |
url |
http://ndltd.ncl.edu.tw/handle/74465959148116216215 |
work_keys_str_mv |
AT yalingchiu atmuserauthenticationbylinkingrandomlygeneratedauthenticationsecretwithpersonalizedsecret AT qiūyǎlíng atmuserauthenticationbylinkingrandomlygeneratedauthenticationsecretwithpersonalizedsecret AT yalingchiu jíyóusuíjīchǎnshēngderènzhèngmìmìyǔgèrénhuàmìmìzhīatmchíkǎrénshēnfēnrènzhèngfāngfǎ AT qiūyǎlíng jíyóusuíjīchǎnshēngderènzhèngmìmìyǔgèrénhuàmìmìzhīatmchíkǎrénshēnfēnrènzhèngfāngfǎ |
_version_ |
1716830583225581568 |