云密码服务中密钥保护体系设计  被引量:1

Design of Key Protection Scheme in Cloud Cryptography Service

在线阅读下载全文

作  者:王雄[1] 冯文浩 池亚平[1] WANG Xiong;FENG Wenhao;CHI Yaping(Beijing Electronic Science and Technology Institute,Beijing 100070,P.R.China)

机构地区:[1]北京电子科技学院,北京市100070

出  处:《北京电子科技学院学报》2021年第4期18-24,共7页Journal of Beijing Electronic Science And Technology Institute

基  金:国家重点研发计划项目“私有云环境下服务化智能办公系统平台”(项目编号:2018YFB1004100);中央高校基本科研业务费项目“密码系统关键技术研究”(项目编号:328201909)资助。

摘  要:为解决云服务在用户隐私、数据保护等安全方面的问题,云密码服务应运而生。面对云服务中用户数量多、需求差异大等特点,云密码服务一般提供海量密钥。如何在云密码服务中结合虚拟密码机设计有效的密钥保护体系成为云密码服务中关键的问题。本文结合虚拟密码机之间的独立、隔离特性,设计以虚拟密码机中密钥库为核心的密钥保护体系。在该体系中,从虚拟密码机、云密码服务两个层面将海量密钥实现分层逐级保护,同时,对密钥的远程管理需求,设计基于密码技术的身份认证且建立安全通信通道。To solve security issues of cloud service in user privacy and data protection, cloud cryptography service has been created. For the characteristics of huge user quantity and great demand diversity in cloud services, cloud cryptography services generally provide massive keys. How to design an effective key protection scheme combining with the virtual cipher machine becomes a key issue in cloud cryptography service. In this paper, a key store in virtual cipher machine centered key protection scheme is designed according to the independence and the isolation between the virtual cipher machines. In the scheme, massive keys are protected hierarchically at the levels of virtual cipher machine and cloud cryptography service. Meanwhile, for the demand of remotely managing the keys, an identity authentication based on cryptography technology is designed and a secure communication channel is established.

关 键 词:密钥保护 云密码服务 虚拟密码机 

分 类 号:TP309.7[自动化与计算机技术—计算机系统结构]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象