Journal of Information Security Research ›› 2019, Vol. 5 ›› Issue (10): 944-952.

Previous Articles    

Summary of Mobile Payment Security Technology

  

  • Received:2019-10-08 Online:2019-10-15 Published:2019-10-08

移动支付安全技术研究综述

夏航宇1,薛聪2,郭晓博2,穆楠2   

  1. 1. 中国科学院大学网络空间安全学院
    2. 中国科学院数据与通信保护研究教育中心
  • 通讯作者: 夏航宇
  • 作者简介:夏航宇 硕士研究生,主要研究方向为数据挖掘、网络空间安全. xiahangyu@iie.ac.cn 薛聪 博士,助理研究员,,主要研究方向为事件分析、数据挖掘. xuecong@iie.ac.cn 中国科学院数据与通信保护研究教育中心 郭晓博 硕士,工程师,主要研究方向为信息安全. guoxiaobo@iie.ac.cn 穆楠 硕士,工程师,主要研究方向为信息安全. munan@iie.ac.cn

Abstract: The popularization of mobile payment has brought convenience yet risks to users information and wealth. In recent years, more and more security technologies in this field have been proposed and applied with the deepening of research. In this article, we introduce PDRR model namely a theory of protection, detection, response and recovery, involving patching of hardware and software, active sniffing of latent threat and proper management toward sudden attack and disasters, which supports the security of mobile payment and gives instruction across the board. Besides, we also review major achievements and research directions in this field including security chip, application security, identity authentication with hardware and biological features, magnet secure transmission as a state of art technology and wireless public key infrastructure, etc. Finally,we also talk about big data and block chain which may add to security in the future. As for the technology of big data, it can be applied for net flow analysis which can be used to defend against advanced persistent threat, while block chain is considered to be a brand framework of mobile payment in the future.

Key words: mobile payment, PDRR model, terminal device, software security, intrusion detection

摘要: 移动支付的普及增加了人们交易的便利性,却同时给用户的信息和财产带来更多风险.近年来随着研究的深入,该领域越来越多的安全技术被提出和应用,介绍了支撑移动支付安全的PDRR模型,包括保护、检测、响应、恢复4个流程,涉及对软硬件的漏洞防护、对威胁的主动嗅探、对攻击和灾害的处理和恢复等方面,为移动支付安全带来全面的策略性指导.除此之外,梳理了几年来主要的安全技术研究成果和研究方向,包括终端设备的安全芯片、应用程序安全、硬件身份认证技术、生物身份认证技术、磁信号传输技术、无线公钥基础设施等.最后讨论了大数据技术在网络流分析、应对高级持续威胁方面的应用,以及区块链作为未来移动支付新体系的前景.

关键词: 移动支付, PDRR模型, 终端设备, 软件安全, 入侵检测