2003年-ECB欧洲央行_Electronic_money_system_security_objectives_according_to_the_common_criteria_methodology_45页_405kb
报告摘要
Summary of the European Central Bank's Electronic Money System Security Objectives (EMSSO) Report
Core Content
The European Central Bank (ECB), in collaboration with the Eurosystem, developed the Electronic Money System Security Objectives (EMSSO) report to define the security requirements for e-money systems in the euro area. This report builds on the 1998 Report on Electronic Money, which addressed the regulatory and monetary policy implications of e-money. The EMSSO report introduces a comprehensive set of security objectives to ensure the reliability, integrity, and security of e-money systems, particularly in an unsecured and untrusted environment. These objectives are aligned with the Common Criteria (CC) methodology, an internationally recognized framework for evaluating IT security.
Main Concepts of the E-money System Model
The e-money system is modelled as a set of sub-systems under the supervision of a System Supervisor, who is responsible for monitoring the creation, circulation, and extinguishment of electronic value (EV). EV is defined as a monetary value represented by a claim on an EV Issuer, which is:
- Stored on an electronic device
- Issued upon receipt of funds for an amount not less in value than the monetary value issued
- Accepted as a means of payment by entities other than the issuer
Sub-systems
Sub-systems are flexible and defined by their ability to:
- Send or receive EV amounts
- Generate Reporting Data (RD)
- Make RD available to the System Supervisor upon request
Key Transactions
- Transactions with CP (Compensation) involve both EV and a corresponding value flow. These are used for payment, loading, refund, collection, etc.
- Transactions without CP involve only EV and are used for recycling, cancellation, and restitution.
EV Life Cycle
The EV life cycle consists of three main phases:
- Creation: EV is injected into the system through specific transactions with CP.
- Circulation: EV circulates within and between sub-systems via transactions with and without CP.
- Extinguishment: EV is removed from the system, typically through transactions with CP, and the EV Issuer is notified via Accounting Data (AD).
Security Objectives
The EMSSO report outlines a list of security objectives that e-money systems must meet, based on the Common Criteria methodology. These objectives are categorized as follows:
Classification of Security Objectives
- Security objectives for the TOE or environment
- Application domains
- Naming convention
Key Security Objectives
- Integrity [INT]: The system must ensure the integrity of EV amounts and other assets.
- Confidentiality [CONF]: Sensitive assets must be kept confidential.
- Identification [ID]: Some components of the e-money system must have an unambiguous identification.
- Authentication [AUTH]: EV transactions and monitoring data exchanges must be authenticated.
- Access Control [ACC]: Unauthorised access to assets is prohibited, even in the event of system malfunction or secret management failure.
- Commitment and Validation [COMM]: Transactions are conducted and validated under a commitment between the involved parties.
- Atomicity [ATOMICITY]: Transactions are either completed or undone entirely.
- Transaction Order [ORD]: Transactions consist of a set of basic operations executed in a predefined order.
- Non-evaporation [EVAP]: Only authorised sub-systems can perform extinguishment transactions.
- Limitations [LIM]: EV amounts are limited during the EV life cycle.
- Traceability [TRAC]: The System Supervisor must be able to trace and audit all strategic events.
- Detection [DETECTION]: The system must detect abnormal events, including asset modification and transaction attribute counterfeiting.
- Reaction [REACTION]: The system must provide means to limit or undo the consequences of abnormal or illicit actions.
- Cryptography and Protocols [CRYP]: State-of-the-art cryptography, protocols, and security procedures are required.
- Secret Management [MNG]: Secrets must be generated, distributed, stored, and renewed properly to preserve confidentiality and integrity.
- Security Update [SECURITY UPDATE]: Periodic security updates are required for all sensitive parts of the system.
- Availability [AVAIL]: The system must ensure service availability even during maintenance.
- Life Cycle [LIFE]: State-of-the-art security procedures are applied throughout the life cycle of EV and sub-systems.
- Partition [PARTITION]: When a sub-system uses applications other than the e-money application, separation is enforced between these applications.
Roles, Actors, and Quasi-Actors
The report defines three main roles in the e-money system:
- Administrator
- Responsibilities: Defines and manages the overall security of the e-money system.
- Trust Level: High
- Risks: Liquidity, compliance, and reputational risks
- Key Tasks: Identifying risks, selecting security controls, managing implementation and operation.
- Operator
- Responsibilities: Participates in implementing and operating the security of the e-money system.
- Trust Level: Moderate
- Risks: Operational, compliance, and reputational risks
- Key Tasks: Ensuring security implementation under the Administrator's coordination.
- User
- Responsibilities: Uses approved devices and follows security procedures.
- Trust Level: Low
- Risks: Fraud in EV transactions, storage, and privacy breaches
- Key Tasks: Minimal security obligations to ensure usability and cost-effectiveness.
Threats and Assumptions
The report identifies several threats that e-money systems may face in an unsecured environment:
- Creation of fake EV: EV that does not represent an EV Issuer's debt.
- Illicit extinguishment of EV: Abnormal and irrevocable EV loss.
- Embezzlement of EV: Unauthorized transfer of EV from its legitimate owner.
- EV theft: Unauthorized access to EV.
- Abuse of the e-money system: Use to infringe regulations.
- Interference with system operation: Malfunction leading to partial or total unavailability.
These threats are addressed through the implementation of the security objectives listed above.
Conclusion
The EMSSO report provides a comprehensive framework for ensuring the security and reliability of e-money systems in the euro area. It defines the security objectives, threats, and roles within the system, and is based on the Common Criteria methodology. The report is intended to support central banks in their oversight of e-money systems and to provide market participants with guidance for their own risk and security analyses.
试读结束,高清完整版pdf/doc/ppt,请点下载