检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:喻潇 田里 刘喆[2,3] 王捷 YU Xiao;TIAN Li;LIU Zhe;WANG Jie(State Grid Hubei Electric Power Research Institute,Wuhan Hubei 430077,China;School of Cyber Science and Engineering,Wuhan University,Wuhan Hubei 430072,China;Key Laboratory of Aerospace Information Security and Trusted Computing of Ministry of Education,Wuhan University,Wuhan Hubei 430072,China)
机构地区:[1]国网湖北省电力有限公司电力科学研究院,武汉430077 [2]武汉大学国家网络安全学院,武汉430072 [3]武汉大学空天信息安全与可信计算教育部重点实验室,武汉430072
出 处:《计算机应用》2018年第A02期164-169,共6页journal of Computer Applications
基 金:国家电网湖北省电力公司科研专项
摘 要:针对当前移动终端中缺乏有效隐私数据保护方案的问题,利用RPMB分区提出了一种隐私数据保护方法。该方法对隐私数据进行加密保护,并且通过认证密钥以及写计数、随机数等机制实现对数据的认证读和认证写操作。首先,因为TrustZone架构在移动终端得到广泛支持,选取TrustZone架构作为RPMB分区载体;然后,基于TrustZone和RPMB两者在安全世界中添加支持模块;再次,通过认证密钥以及写计数、随机数等组件实现对数据的认证读和认证写操作;最后,搭建实验平台对环境作出仿真,同时模拟攻击测试。实验结果表明,该方法对读写操作的重放攻击有较好的防御功能。In view of the lack of effective privacy data protection scheme in mobile terminals,a privacy data protection method was proposed based on RPMB partition.The privacy data was encrypted and the authentication and authentication of the data was realized through authentication key,write count and random number.First,because the TrustZone architecture was widely supported on mobile terminals,the TrustZone architecture was chosen as the RPMB partition carrier.Then,modules were supported by TrustZone and RPMB in the secure world.Thirdly,through authentication key,write count,random number and other components,the data authentication read and authentication write operations were realized.Finally,an experiment platform was built to simulate the environment,and attacks.The experimental results show that this method can defend against replay attacks on read-write operations.
关 键 词:隐私数据保护 RPMB分区 TRUSTZONE eMMC存储 认证
分 类 号:TP309[自动化与计算机技术—计算机系统结构]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:13.58.187.29