首页 馆藏资源 舆情信息 标准服务 科研活动 关于我们
现行 X9 X9.59-2006(R2013)
到馆提醒
收藏跟踪
购买正版
Electronic Commerce for the Financial Services Industry: Account Based Secure Payments Objects 金融服务业的电子商务:基于账户的安全支付对象
发布日期: 2006-05-24
1范围本标准涉及以下内容:A)支付模式描述本标准描述了基于账户的电子支付模式。它确定了 支付流程的不同组成部分以及这些角色之间的信息流。角色是 希望付款的消费者、提供价值的商户及其各自的 金融机构、消费金融机构和商业金融机构。B) 安全对象规范本标准规定了电子支付对象的集合,并参考了数字签名技术 保护他们的内容。这些对象都是根据它们需要如何构造、签名和签名来定义的 在代表消费者和商家的计算机器中验证。具体的语法是 指定,以便可以在任何可以访问签名的位置构造或验证签名 消费者的公钥和相关数据。一项商业建议是,支付路线 不接受与本标准定义的安全支付对象一起使用的代码(或PAN) 在未经身份验证的交易中有效。文中给出了几个使用场景,以展示真实场景的示例 标准对象可能适用的应用。支付信息可能需要保密,本协议既不要求也不排除保密 标准谨慎的实施者可以选择进行风险评估,以确定是否需要 保密。此外,政策问题,包括双方之间协议的条款和条件,也不适用 包括在本标准中。虽然标准中描述的一些信息必须能够在交换后保存 在合作的金融机构之间,它在任何特定支付协议中出现的语法都不明确 明确规定。
1 ScopeThis standard addresses the following:A) Payment Model DescriptionThis standard describes a model of account based electronic payments. It identifies the roles played by different components of the payment process and the flow of information between those roles. The roles are the consumer, who wishes to make a payment, a merchant which provides value, and their respective Financial Institutions, the consumer financial institution and the merchant financial institution.B) Secure Object SpecificationsThis standard specifies a collection of electronic payment objects and references digital signature techniques to secure their content. The objects are all defined in terms of how they need to be constructed, signed and verified in computing machinery that is acting on behalf of a consumer and a merchant. A concrete syntax is specified in order that the signature can be constructed or verified at any location that has access to the consumer's public key and associated data. A business recommendation is made that the payment routing code (or PAN) used in conjunction with secure payment objects defined by this standard is not accepted as valid in non-authenticated transactions. Several usage scenarios are given to show examples of real applications where the standard objects may be applicable.Confidentiality for the payment information may be desired and is neither required, nor precluded, by this standard. Prudent implementers may choose to conduct a risk assessment to determine the need for confidentiality. Also policy issues, including terms and conditions of the agreements between the parties, are not covered in this standard. While some of the information described in the standard must survive interchange between cooperating financial institutions, the syntax of how it appears in any particular payment protocol is not specified.
分类信息
发布单位或类别: 未知国家-其他未分类
关联关系
研制信息
相似标准/计划/法规