首页 馆藏资源 舆情信息 标准服务 科研活动 关于我们
现行 X9 X9.24-1-2017
到馆提醒
收藏跟踪
购买正版
Retail Financial Services Symmetric Key Management Part 1: Using Symmetric Techniques 零售金融服务对称密钥管理第1部分:使用对称技术
发布日期: 2017-06-08
ANSI X9。2017年1月24日涵盖了用于金融服务的键入材料的手动和自动管理,如销售点(POS)交易(借记和信用)、自动柜员机(ATM)交易、终端和金融机构之间的消息,以及收单机构、交换机和发卡机构之间的交换消息。本标准的这一部分专门涉及使用对称技术管理对称密钥。X9中介绍了由非对称密钥保护的对称密钥的要求。24-2. 本部分中所述的任何要求并不意味着使第2部分中规定的要求无效。 本部分标准规定了键控材料管理的最低要求。涉及密钥管理生命周期的所有组成部分,包括密钥材料的生成、分发、利用、存储、归档、更换和销毁。机构的密钥管理过程,无论是在计算机或终端中实施,都不得以比本文所述的安全性、保护性或控制性更低的方式实施或控制。其目的是,如果两个节点根据本标准的这一部分实现了密钥管理方法、密钥识别技术和密钥分离方法的兼容和安全版本,那么它们将在应用程序级别互操作。 节点互操作性可能需要其他特性;然而,本标准的这一部分不包括消息格式、通信协议、传输速度或设备接口等特性。DUKPT算法的定义在X9中给出。24第三部分。本标准之前版本中包含的与DUKPT实施相关的信息已移至该标准。
ANSI X9.24-1-2017 covers both the manual and automated management of keying material used for financial services such as point-of-sale (POS) transactions (debit and credit), automated teller machine (ATM) transactions, messages among terminals and financial institutions, and interchange messages among acquirers, switches and card issuers. This part of this standard deals exclusively with the management of symmetric keys using symmetric techniques. Requirements for symmetric keys protected by asymmetric keys are addressed in X9.24-2. Any requirements stated in this part are not meant to invalidate the requirements provided for in Part 2. This part of the standard specifies the minimum requirements for the management of keying material. Addressed are all components of the key management life cycle, including the generation, distribution, utilization, storage, archiving, replacement and destruction of the keying material. An institution's key management process, whether implemented in a computer or a terminal, is not to be implemented or controlled in a manner that has less security, protection, or control than described herein. The intention is that if two nodes implement compatible and secure versions of key management methods, key identification techniques, and key separation methods in accordance with this part of this standard, they will be interoperable at the application level. Other characteristics may be necessary for node interoperability; however, this part of this standard does not cover such characteristics as message format, communications protocol, transmission speed, or device interface.The definition of the DUKPT algorithm is addressed in X9.24 Part 3. Information contained in previous versions of this standard related to the implementation of DUKPT has been moved to that standard.
分类信息
发布单位或类别: 未知国家-其他未分类
关联关系
研制信息
相似标准/计划/法规