Retail Financial Services Symmetric Key Management Part 2: Using Asymmetric Techniques for the Distribution of Symmetric Keys
零售金融服务对称密钥管理第2部分:使用不对称技术分发对称密钥
发布日期:
2016-11-25
ANS X9.24的这一部分涵盖了设备初始信任的建立和用于金融服务的密钥材料的管理,如销售点(POS)交易、自动柜员机(ATM)交易、终端和金融机构之间的消息以及收单机构、交换机和发卡机构之间的交换消息。X9.24本部分的范围可能适用于基于互联网的交易,但仅当此类应用包括使用SCD(如第7节所定义)时。
ANS X9.24第1部分第2节),以保护私钥和对称密钥。ANS X9.24的这一部分涉及使用非对称技术管理对称密钥和使用对称密钥存储非对称私钥。将来可能会创建其他部分来解决密钥管理的其他方法。ANS X9.24的这一部分规定了非对称密钥材料和对称密钥管理的最低要求,用于确保非对称密钥对的私钥作为密码存储在数据库上时的机密性和完整性。
本文介绍了关键管理生命周期的所有组成部分,包括生成、分发、利用、存储、归档、更换和销毁。还讨论了在发生关键妥协时采取行动的要求。ANS X9.24的这一部分概述了密钥传输和密钥协议协议中涉及的密钥,并参考了其他ANSI标准(如适用)。
This part of ANS X9.24 covers the establishment of device initial trust and management of keying material used for financial services such as point of sale (POS) transactions, automatic teller machine (ATM) transactions, messages among terminals and financial institutions, and interchange messages among acquirers, switches and card issuers. The scope of this part of X9.24 may apply to Internet-based transactions, but only when such applications include the use of a SCD (as defined in section 7.2 of ANS X9.24 Part 1) to protect the private and symmetric keys. This part of ANS X9.24 deals with management of symmetric keys using asymmetric techniques and storage of asymmetric private keys using symmetric keys. Additional parts may be created in the future to address other methods of key management.This part of ANS X9.24 specifies the minimum requirements for the management of asymmetric keying material and symmetric keys used for ensuring the confidentiality and integrity of the private keys of asymmetric key pairs when stored as cryptograms on a database. Addressed are all components of the key management life cycle including generation, distribution, utilization, storage, archiving, replacement and destruction. Requirements for actions to be taken in the event of key compromise are also addressed. This part of ANS X9.24 presents overviews of the keys involved in the key transport and key agreement protocols, referencing other ANSI standards where applicable.