节点文献
密码芯片安全升级保护机制静态部分的设计及实现
【作者】 张九华;
【导师】 范明钰;
【作者基本信息】 电子科技大学 , 密码学, 2005, 硕士
【摘要】 随着计算机网络技术的飞速发展及广泛应用,信息安全技术愈来愈受到人们的重视,并且逐步在网络技术的发展及应用中扮演着备受关注的角色。由于信息安全技术的支撑点是现代密码技术,而现代密码技术的核心是各种密码算法,因此,专用密码算法芯片在信息安全技术中起着至关重要的作用,信息安全技术发展到今天也被称为已经进入了芯片密码年代。当今国内密码芯片的制作方式,主要是采用制作成ASIC 的形式或者利用特种FPGA(反熔丝型FPGA)的形式。这两种形式普遍存在着一个问题,就是一旦针对某种密码算法的密码芯片制作完成,其算法功能在同一块芯片上都是不可再更改的。这样,如果为了安全的需要而要求更改密码算法时就只有抛弃原先的芯片而重新开发新的密码芯片,这就需要较大的开发成本和一定的开发周期。针对上述情况,一种密码算法安全升级保护机制[1] 在国内首次从理论上提出了一种解决方法并且获得了国家专利(专利号:2003101041.6),利用此机制可以方便灵活的安全升级密码芯片而又可以降低开发成本。本文就是在这一机制的理论基础之上,对其中的静态保护部分进行进一步的研究,提出了具体的设计和硬件实现方案。本文在介绍了安全保护机制的设计构架的基础上,主要对其中的静态保护部分的设计及硬件实现进行详细的介绍。其中,详细介绍了静态保护机制的设计思路及工作流程。根据静态保护机制的设计思想,整个静态保护部分大致又可以划分为参数检验部分、口令验证部分、摘要验证部分、摘要算法功能部分以及控制部分等五个部分。文中详细介绍了各个部分的工作原理、工作流程及硬件实现规划,并且利用VHDL硬件描述语言对各个部分进行了描述实现。最后利用ModelSim仿真工具对静态保护模块的各个功能子模块进行了功能仿真测试,同时在文中提供了一些仿真验证波形,并且对测试结果进行了分析。上述一系列的工作,一方面验证了本设计的可行性,同时也是对密码芯片安全升级保护机制这一技术的实用化所做出的有意义的探讨。
【Abstract】 More and more people attach importance to the study of the informationsecurity technique with the fast development and the extensive application ofcomputer network technology. The information security technique will gradually acta highly anticipated role in the development of the network technology. Because thecore of the modern encryption technique is encryption algorithm, so the special chipfor encryption algorithm is the most important part in the information securitytechnique. Currently, the method that people make the special chip for encryption ismaking use of ASIC or special FPGA (example based on Anti-fuse technology).However, the kind of algorithm chip has a weakness that the algorithm in the chipwill never be changed after finishing chip design and implementation unless makinganother different chip if the encryption algorithm wants to be changed or thesecurity system that based on the algorithm chip. So, under the situation, a lot ofmoney and time must be spent in order to update security system. In this paper, amethod been presented for the first time which can protect crypto chip to upgrade itsalgorithm after finishing chip design and implementation.In this paper the design idea of the secure upgrading mechanism to crypto chipand the design and hardware implementation of the part of static protects areintroduced which are important parts in the complete secure upgrading mechanism.Especially, this paper introduces the design idea and workflow of the static protectmodule. According to the design idea, the static protect module can be set off fiveparts: parameter check module, password validate module, digest validate module,MD5 algorithm module and control module. Particularly all modules’workprinciple and workflow and layout for hardware implementation are introduced. Inaddition, all of the modules in VHDL hardware description language are describedand simulation tools finish all modules’function simulation and some functionsimulation waves are provided. All the works validate our design idea and, on theother hand, bring some help to the Secure Upgrading Mechanism to Crypto Chipand promote its development aiming at practicality.
- 【网络出版投稿人】 电子科技大学 【网络出版年期】2005年 07期
- 【分类号】TN918.1
- 【被引频次】1
- 【下载频次】153