为提高网上支付系统的安全性,提出一种面向服务架构的松耦合的安全体系。该安全体系利用企业服务总线,灵活集成公钥基础设施、安全令牌、加密、签名、身份认证、角色访问控制等安全服务,增强了网上支付的安全。利用π演算对USBKey双因素认证服务建模,用形式化的方法验证了细粒度安全服务组合成粗粒度安全服务的正确性。经过某商业银行网上支付系统的实践,表明这种基于企业服务总线的Web服务系统,是一种具有安全性和便利性的安全解决方案。
To improve the security of Internet payment system, the service-oriented loosely coupled security architecture was proposed. Based on Service-Oriented Architecture (SOA), integrating the enterprise service bus and other security services such as Public Key Infrastructure (PKI), security token, encryption, signature, authentication and access control, etc. , the Internet payment security was enhanced. Furthermore, the USBKey two-factor authentication service model based on π-calculus was also proposed. A formal method was used to verify the process of the fine-grained services combining with coarse grained service. The design was incorporated into Internet payment system in commercial bank. Application results showed that it was effective and convenient.