Home Operation and Maintenance Safety How to answer HCE security questions

How to answer HCE security questions

May 16, 2023 pm 03:46 PM
hce

In recent projects, we are often asked: Is HCE safe?

My answer is: relatively safe.

After hearing my answer, many people may start to say, a certain bank has launched HCE application, why is it unsafe?

In fact, there are two HCE application scenarios: online mode and offline mode.

Online mode:

Even if there are security issues, the processes involving related keys and calculations are completed in the background, so it falls within the scope of network security. However, large-scale key leakage will not occur. Currently, all HCE applications launched by banks are in online mode.

Offline mode:

Relevant keys, sensitive data, amounts and other information will be stored inside the phone. Android phones can be easily rooted, which can cause data to be read and copied, so things can get tricky.

Pure HCE security solution:

  • Transaction key: protected by session key. The session key will change each time you log in, and the transaction key will be modified. Convert encryption.

  • Sensitive data and amount: protected by session key, encrypt all 0s with data plaintext, and generate check value; when verifying sensitive data and amount, decrypt first, Then compare the check values.

Security level: Algorithm hidden

Disadvantages: Unable to prevent copying.

HCE TEE security solution:

  • HCE application implements simulated industry applications.

  • TEE stores keys, sensitive data, amounts, etc.



Security level: Kernel security

Disadvantages: TEE adaptation rate is low, and Need to restart the phone.

The above is the detailed content of How to answer HCE security questions. For more information, please follow other related articles on the PHP Chinese website!

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)