论文部分内容阅读
SSL能够为电子交易提供认证性、私有性、完整性服务,却无法保证电子交易的不可抵赖性,无法为事后提供稳定的验证性。文章针对HTTP协议,在SSL基础上设计了SHL协议,有效地保证了电子交易的不可抵赖性。SHL协议工作在交易服务器和客户端,对交易请求和响应进行签名、验证、记录。SHL有SPC和SPS两个部分组成,SPC和SPS之间使用SSL安全通信。SPC对客户端请求签名,验证服务器签名;SPS验证客户端签名,对服务器请求签名。SHL为交易提供稳定的验证性,保证交易的不可抵赖性。
SSL can provide authenticity, privacy and integrity services for electronic transactions. However, it can not guarantee the non-repudiation of electronic transactions and can not provide stable and verifiable after-events. This article designed the SHL protocol based on SSL for HTTP protocol, effectively ensuring the non-repudiation of electronic transactions. SHL protocol work in the trading server and client, the transaction request and response to sign, verify, record. SHL has SPC and SPS two parts, SPC and SPS using SSL secure communication. The SPC signs the client’s request, verifies the server’s signature, SPS verifies the client’s signature, and signs the server’s request. SHL provides a stable verification of the transaction, to ensure the non-repudiation of the transaction.