高性能密码服务系统体系结构设计  被引量:2

Design of High-Performances Cryptographic Service System Architecture

在线阅读下载全文

作  者:容晓峰[1] 李增欣[2] 刘平[2] 周利华[1] 

机构地区:[1]西安电子科技大学计算机网络与信息安全教育部重点实验室 [2]国家信息安全工程技术研究中心,北京100093

出  处:《吉林大学学报(信息科学版)》2005年第4期408-415,共8页Journal of Jilin University(Information Science Edition)

基  金:国家十五科技攻关基金资助项目(2002BA103A04)

摘  要:随着大型电子商务和电子政务系统中客户数量的增多,主机端密码系统的性能成为提供安全服务限制因素,针对该问题提出了一种基于高性能、可编程密码模块硬件的密码服务系统体系结构。通过设计统一设备API(ApplicationProgramInterface)接口和在模块内的芯片之间实现并行密码运算,该方法可以实现系统密码运算的高性能。该系统已在IBMServices345服务器和密码模块硬件上实现。通过对1024位RSA签名性能与并行密码模块数目间的关系进行测试分析,结果显示,基于该体系结构实现的密码服务系统是高性能的和可扩展的。With more and more clients attached to a host, performance of cryptographic operations at the host has become a constraint that prevents the achievement of acceptable secure services at large e-commerce and e-governments. To overcome this limitation, the authors propose a cryptographic service system architecture, based on the hardware of high-performance, programmable secure crypto module. This architecture provides a general framework that can provide well scalability by using a general device API(Application Program Interface),and obtain high performance by carrying cryptography computations in parallel between crypto chips in crypto modules. The system is implemented on an IBM Services345 machine and hardware crypto modules. Preliminary measurements are also performed to study the trade-off between numbers of crypto modules parallel computing and performance of generate 1 024-bit RSA digital signature. Results indicate that the system implemented by the architecture with high performance and scalability.

关 键 词:密码芯片 密码模块 密码服务系统 并行计算 可扩展性 

分 类 号:TP393.07[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象