银联卡受理商户信息系统安全规范(Q/CUP 081-2018)
本规范适用于所有银联卡受理商户信息系统,凡是涉及存储、处理、传输持卡人数据的所有商户、服务提供商必须满足准入的基本安全要求。
1 范围 ...........................................................................................................................................................1
2 规范性引用文件........................................................................................................................................1
3 术语、定义和缩略语................................................................................................................................1
3.1 访问控制 Access Control...................................................................................................................1
3.2 物理访问控制 Physical Access Control.............................................................................................1
3.3 逻辑访问控制 Logical Access Control...............................................................................................1
3.4 账户信息 Account Information.........................................................................................................2
3.5 主账号 Primary Account Number; PAN ............................................................................................2
3.6 身份鉴别 Authentication ..................................................................................................................2
3.7 生物识别 Biometrics.........................................................................................................................2
3.8 密码鉴定 Cryptographic Authentication ..........................................................................................2
3.9 信息 Information...............................................................................................................................2
3.10 不可逆加密 Irreversible Encryption..................................................................................................2
3.11 公共网络 Public Network..................................................................................................................2
3.12 静态密码 Static Password.................................................................................................................3
3.13 动态密码 Dynamic Password............................................................................................................3
3.14 保密性 Confidentiality ......................................................................................................................3
3.15 完整性 Integrity ................................................................................................................................3
3.16 敏感数据(信息) Sensitive Data(Information) ........................................................................3
3.17 可用性 Availability ............................................................................................................................3
3.18 敏感性 Sensitivity..............................................................................................................................3
3.19 个人标识代码 Personal Identification Number; PIN ........................................................................3
3.20 卡片有效期 Expiration Date .............................................................................................................3
3.21 卡片验证码 Card Verification Number.............................................................................................4
3.22 双因素验证 Two-factor Authentication ...........................................................................................4
3.23 双重控制 Dual Control......................................................................................................................4
3.24 支付标记 payment token..................................................................................................................4
3.25 TR Token Requestor...........................................................................................................................4
3.26 DMZ 隔离区 Demilitarized Zone .......................................................................................................4
3.27 安全审计 Security Audit....................................................................................................................4
3.28 威胁 Threat........................................................................................................................................4
3.29 授权 Authorization ............................................................................................................................4
3.30 银行卡 Bank Card..............................................................................................................................4
3.31 密钥加密密钥 Key Encryption Key; KEK ...........................................................................................5
3.32 工作密钥 Working Key; WK ..............................................................................................................5
4 系统架构 ...................................................................................................................................................5
4.1 独立客户端模式 ...............................................................................................................................5
4.2 集成SDK模式.....................................................................................................................................6
4.3 调用DLL链接库模式 .........................................................................................................................6
4.4 基于浏览器HTML5模式....................................................................................................................7
5 通用安全要求............................................................................................................................................7
5.1 数据安全 ...........................................................................................................................................7
5.2 访问控制安全 ...................................................................................................................................9
5.3 密钥安全 .........................................................................................................................................10
6 组件安全要求..........................................................................................................................................11
6.1 应用系统安全 .................................................................................................................................11
6.2 客户端安全 .....................................................................................................................................12
6.3 通信安全 .........................................................................................................................................13
7 管理要求 .................................................................................................................................................13
7.1 系统开发安全 .................................................................................................................................13
7.2 系统发布与变更安全 .....................................................................................................................14
7.3 人员安全培训 .................................................................................................................................15
7.4 实施准则更新 .................................................................................................................................15
附录:《实施准则》 ......................................................................................................................................15
- 银行卡受理终端安全规范 第2部分:受理商户信息系统(JR/T 0120.2-2016)
- 中国人民银行:数字函证金融应用安全规范(JR/T 0234-2021)
- 中国支付清算协会:移动金融基于声纹识别的安全应用评估规范(T/PCAC 0010-2021)
- 中国人民银行:金融数据安全 数据生命周期安全规范(JR/T 0223-2021)
- 国家医疗保障局:医疗保障信息系统安全开发规范(XJ-AQTY.01-2019)
- 金融分布式账本技术安全规范(JR/T 0184-2020)
- 商业银行应用程序接口安全管理规范(JR/T 0185-2020)
- 移动金融客户端应用软件安全管理规范(JR/T 0092-2019)
- 银联卡受理终端安全规范 第2卷:产品卷 第6部分:智能销售点终端(Q/CUP 007.2.6-2016)
- 银联卡受理终端安全规范 第1卷:基础卷 第4部分:硬件要求(Q/CUP 007.1.4-2017)