摘要
QR码凭借诸多优势得以广泛应用的同时,QR码解码工具也迅速发展,随之而来的QR码的信息安全问题也备受关注。文中提出了一种用哈希函数SHA-1对QR码的部分敏感信息进行加密,用加密生成的摘要信息替换原始QR码中的敏感信息,用敏感信息的摘要信息和原始QR码中的非敏感信息重新生成新的QR码。用新的QR码替换原始QR码,这样攻击者就无法通过解码工具来直接获取原始QR码中的敏感信息。攻击者即使获得了原QR码中敏感信息的摘要信息,由于SHA-1良好的单向性等性质,要求出其对应的原始敏感信息至少在计算上也是不可行的。
The QR code has many advantages. With the widely application of the QR code, the decoding tools were developed rapidly. The security has been concerned. In this paper, a method that the sensitive information of QR code is encrypted with SHA-1 is put forward. Then, the sensitive information is replaced with its message digest. The new QR code is consisted of the message digest of the sensitive information and the remained non-sensitive message in the original QR code. The attackers can hardly get the sensitive information through the decoding tools. Even if the encrypted information of the sensitive information is intercepted, decoding it is infeasible in the calculation for the good nature of one- way of SHA-1.
出处
《信息技术》
2012年第11期90-92,95,共4页
Information Technology