Static data authentication means that the terminal uses a digital signature scheme based on public key technology. Unauthorized data changes are found after personalization. Static data authentication requires a high-security authentication center to sign the publisher's public key. Each terminal meeting this specification must keep the public key of the corresponding authentication center for each application it can identify.
Sda is a very useful tool. Through it, we can gradually shorten the distance between the actual achievement and the goal, thus achieving the goal. In addition, sda (Skills Development Activity) is a key problem to solve enterprise management. By establishing cross-functional teams and using scientific thinking methods and group activities, the most effective solutions can be found.
Description of static data authentication process:
1. The publisher's key management system generates the publisher's public/private key pair PI and SI, and sends the public key PI to the root CA.
2. The root CA digitally signs the publisher's public key PI with its own private key SCA to generate the publisher's certificate, which is returned to the publisher's key management system together with the public key information of the root CA.
3. The issuer's key management system digitally signs the card static data with the issuer's private key SI, and sends the signing result and the issuer's certificate to the card issuing system.
4. The card issuing system will write the card issuing bank certificate and digital signature into each card during personalization.
5. The root CA sends its public key PCA to the terminal management system through the acquiring bank.
6. The terminal management system of the acquiring bank remotely downloads the root CA public key PCA to the terminal.
7. The 7.IC card performs static data authentication for offline transactions, and the receiving terminal completes the following processes.
8. The terminal reads the issuer's certificate and signature data from the card, and uses CA public key PCA to recover the issuer's public key PI.
9. The terminal decrypts the card signature data using the public key PI recovered by the issuing bank.
10. The terminal compares the decryption result with the static data of the card and saves the comparison result.
Reference to the above content: Baidu Encyclopedia -SDA