针对HCE技术中移动客户端计算能力有限、存储敏感数据易泄密、身份认证复杂等问题,引入无证书公钥密码思想和标记化,提出一个可双向认证的HCE移动支付方案,给出移动客户端易泄密的解决方法,实现双向身份认证,提高信息传送通道的安全性。分析结果表明,该方案具有公钥密码的机密性、完整性和不可否认性,满足前向安全性,是一个安全可靠、使用便捷的移动支付方案。
To solve the problems of low computing capacity, key data leakage and complex identity authentication of the mobile terminal in HCE technology, the idea of certificateless public cryptography and tokenization was introduced. A HCE mobile payment scheme which supported two-way authentication was proposed. A solution was presented to make up the defect of the mobile terminal without secure element, realizing the two way authentication, and improving the security of the information transmission channel. The analysis shows that the scheme has the characteristics of confidentiality, integrity and non-repudiation of the public key cryptography. It also satisfies the forward security. The scheme is safe and reliable for mobile payment.