ANSI X9.8 Part 1-2003 Banking - Personal Identification Number Management and Security - Part 1 PIN protection principles and techniques for online PIN verification in ATM & POS sy.pdf
《ANSI X9.8 Part 1-2003 Banking - Personal Identification Number Management and Security - Part 1 PIN protection principles and techniques for online PIN verification in ATM & POS sy.pdf》由会员分享,可在线阅读,更多相关《ANSI X9.8 Part 1-2003 Banking - Personal Identification Number Management and Security - Part 1 PIN protection principles and techniques for online PIN verification in ATM & POS sy.pdf(59页珍藏版)》请在麦多课文档分享上搜索。
1、 American National Standard for Financial Services X9.82003 BANKING - PERSONAL IDENTIFICATION NUMBER MANAGEMENT AND SECURITY Part 1: PIN protection principles and techniques for online PIN verification in ATM their existence does not in any respect preclude anyone, whether he has approved the standa
2、rds or not from manufacturing, marketing, purchasing, or using products, processes, or procedures not conforming to the standards. The American National Standards Institute does not develop standards and will in no circumstances give an interpretation of any American National Standard. Moreover, no
3、person shall have the right or authority to issue an interpretation of an American National Standard in the name of the American National Standards Institute. Requests for interpretations should be addressed to the secretariat or sponsor whose name appears on the title page of this standard. CAUTION
4、 NOTICE: This American National Standard may be revised or withdrawn at any time. The procedures of the American National Standards Institute require that action be taken to reaffirm, revise, or withdraw this standard no later than five years from the date of approval. Published by Accredited Standa
5、rds Committee X9, Incorporated Financial Industry Standards P. O. Box 4035 Annapolis, MD 21403 X9 Online http:/www.x9.org Copyright 2003 by Accredited Standards Committee X9, Incorporated All rights reserved. No part of this publication may be reproduced in any form, in an electronic retrieval syste
6、m or otherwise, without prior written permission of the publisher. Printed in the United States of America Copyright American National Standards Institute Provided by IHS under license with ANSINot for ResaleNo reproduction or networking permitted without license from IHS-,-,-ANS X9.82003 2003 All r
7、ights reserved iiiThis ANSI Standard is based on ISO 9564-1:2002(E) Banking Personal Identification Number (PIN) management and security Part 1: PIN protection principles and techniques for online PIN verification in ATM and POS systems. The ISO 9564-1:2002(E) has been reproduced in its entirety wit
8、h the addition of “ANSI NOTE“s where required to adapt the text for use as an ANSI Standard. Where applicable, references to ANSI standards have been added. Specific references to “ISO 9564“ in the original ISO 9564 have been replaced with “ISO 9564 this standard“, for the purpose of clarity. “ANSI
9、NOTE“s have been added to the following sections of ISO 9564-1:2001(E): 5.1 6.2 (two Notes) 6.3.3 7.2.2 7.3.3.3 8.3.1 Annex A Annex E Annex A, General Principles of Key Management, has been superseded by ANS X9.24-2002, Retail Financial Services Symmetric Key Management Part 1: Using Symmetric Techn
10、iques Annexes A, B, C, D, E, F and G are informative annexes, presented for information only. ANS X9.8 consists of the following parts, under the general title Banking - Personal Identification Number (PIN) Management and Security: - Part 1: PIN protection principles and techniques for online PIN ve
11、rification in ATM therefore, PIN management procedures should implement preventive measures to reduce the opportunity for a breach in security and aim for a “high“ probability of detection of any illicit access or change to PIN material should these preventive measures fail. This applies at all stag
12、es of the generation, exchange and use of a PIN, including those processes that occur in cryptographic equipment and those related to communication of PINs. This part of ISO 9564 this standard is designed so that Issuers can uniformly make certain, to whatever degree is practical, that a PIN, while
13、under the control of other institutions, is properly managed. Techniques are given for protecting the PIN-based customer authentication process by safeguarding the PIN against unauthorised disclosure during the PINs life cycle. This standard includes the following annexes: a) annex A covers general
14、principles of key management; b) annex B covers techniques for PIN verification; c) annex C deals with implementation concepts for a PIN entry device for online PIN encipherment; d) annex D identifies an example of pseudo-random PIN generation; e) annex E indicates additional guidelines for the desi
15、gn of a PIN entry device; f) annex F specifies guidance on clearing and destruction procedures for sensitive data; g) annex G gives information for customers. Copyright American National Standards Institute Provided by IHS under license with ANSINot for ResaleNo reproduction or networking permitted
16、without license from IHS-,-,-ANS X9.82003 viii 2003 All rights reservedIn ISO 9564-2, this standard - part 2 approved encipherment algorithms to be used in the protection of the PIN are specified. Application of the requirements of this part of ISO 9564 this standard requires bilateral agreements to
17、 be made, including the choice of algorithms specified in ISO 9564-2 this standard - part 2. This part of ISO 9564 this standard is one of a series that describes requirements for security in the retail banking environment, as follows: ISO 9564-2:1991, Banking - Personal Identification Number manage
18、ment and security - Part 2., Approved algorithm(s) for PIN encipherment. ISO DIS 9564-3,Banking - Personal Identification Number management and security - Part 3, PIN protection principles for offline PIN handling in ATM and POS systems1ISO 10202, Financial transaction cards - Security architecture
19、of financial transaction systems using integrated circuit cards (all parts) ISO 11568, Key management (retail) - (all parts) ISO 13491, Secure cryptographic devices - (all parts) ISO 15668, Banking - Financial transaction cards - Secure file transfer (retail) ISO DIS 16609, Banking - requirements fo
20、r message authentication1Suggestions for the improvement of this standard will be welcome. They should be sent to the ASC X9 Secretariat, Accredited Standards Committee X9, Incorporated, P. O. Box 4035, Annapolis, MD 21403. This Standard was processed and approved for submittal to ANSI by the Accred
21、ited Standards Committee on Financial Services, X9. Committee approval of the Standard does not necessarily imply that all the committee members voted for its approval. The X9 committee had the following members: Harold Deal, X9 Chairman Vincent DeSantis, X9 Vice-Chairman Cynthia Fuller, Executive D
22、irector Isabel Bailey, Managing Director Organization Represented Representative ACI Worldwide Cindy Rink ACI Worldwide Jim Shafer American Bankers Association Doug Johnson American Bankers Association Don Rhodes American Bankers Association Stephen Schutze American Bankers Association Michael Scull
23、y American Express Company Mike Jones American Express Company Gerry Smith American Express Company Barbara Wakefield American Financial Services Association John Freeman American Financial Services Association Mark Zalewski 1To be published Copyright American National Standards Institute Provided b
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ANSIX98PART12003BANKINGPERSONALIDENTIFICATIONNUMBERMANAGEMENTANDSECURITYPART1PINPROTECTIONPRINCIPLESANDTECHNIQUESFORONLINEPINVERIFICATIONINATMPOSSYPDF

链接地址:http://www.mydoc123.com/p-439648.html