可信密码模块应用层接口优化设计与实现  被引量:3

Optimization Design and Implementation of Application Layer Interface of Trusted Cryptography Module

在线阅读下载全文

作  者:王冠 严志伟 Wang Guan;Yan Zhiwei(Faculty of Information Technology,Beijing University of Technology,Beijing 100124;Beijing Key Laboratory of Trusted Computing(Beijing University of Technology),Beijing 100124)

机构地区:[1]北京工业大学信息学部,北京100124 [2]可信计算北京市重点实验室(北京工业大学),北京100124

出  处:《信息安全研究》2020年第4期354-361,共8页Journal of Information Security Research

摘  要:可信计算技术是保障信息安全的一种重要技术手段,其实现依赖于可信芯片,可信密码模块(trusted cryptography module,TCM)是符合中国标准的一种可信芯片.目前,《可信密码支撑平台功能与接口规范》中定义的TCM的应用接口存在使用过程复杂、易用度不高的问题,阻碍可信计算技术的应用.为解决这些问题,对规范中的接口设计进行优化,提出了一套面向应用层的可信密码模块接口.该接口按照功能划分为4个模块,分别是密码算法服务模块、TCM资源服务模块、身份认证服务模块、平台保护服务模块.此外,提出了采用上下文资源管理与TCM资源回收的优化方法,该方法有效地提高了接口的易用度,增强了对TCM资源回收能力.实验结果表明:该套优化设计的接口相对于规范中的接口增加的时间开销不到10%,但是,可以显著降低核心代码的行数.Trusted computing technology is an important technical to ensure information security which implementation depends on trusted chip.The trusted cryptography module(TCM)is a kind of trusted chip that conforms to Chinese standards.Currently,the TCM application interface defined in functionality and interface specification of cryptographic support platform for trusted computing has some problems,such as the use process is complex and low ease of use,which hinders the application of trusted computing technology.To solve these problems,a set of optimized TCM application layer interface is proposed,which is divided into four modules according to functions,namely cryptography algorithm service module,TCM resource service module,identity authentication service module and platform protection service module.In addition,an optimized method about context resources management and TCM resources recovery is proposed,which can effectively improve the usability of the interface and enhance the recovery capability of TCM resources.Experimental results show that the optimized interface increases the time cost by less than 10%compared with the interface in the specification,but it can significantly reduce the number of lines of core code.

关 键 词:可信计算 可信密码模块 信息安全 性能优化 接口 

分 类 号:TP309[自动化与计算机技术—计算机系统结构]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象