节点文献

基于PKI的可信计算体系研究及其应用

Research and Applications of Trusted Computing System Based on PKI

【作者】 段斌

【导师】 王键;

【作者基本信息】 湘潭大学 , 计算数学, 2004, 博士

【摘要】 PKI(公开密钥基础设施)一词被解释成为是一种框架体系,通过它,因特网上的用户可实现安全信息数据的交换,满足保密性,完整性,真实性及不可否认性的安全需求。一个实体的可信是指,它的行为总是以所期望的方式,朝着预期的目标。可信计算的基本思路是:首先构建一个信任根,信任根的可信性由物理安全和管理安全确保。再建立一条信任链,从信任根开始,一级认证一级,一级信任一级,从而把这种信任扩展到整个可信计算领域。这里,我们将结合PKI和可信计算两类技术,构建分布式信息交换系统的可信计算体系,应用于教育、电力等领域的实际需要。 本文分为三个部分。第一部分,从TCG(可信计算组织)规范中明确的TPM(可信平台模块)体系结构对密码算法的要求入手,讨论AES和RSA等典型密码算法的算法原理和便于硬件实现的优化方法,以及这些算法在FPGA或DSP中的硬件快速实现方法。对AES解密算法进行等效变换,使得解密与加密硬件实现的电路结构相近,克服原算法加密与解密运算的实现仅能使用少部分相同电路的不足;另外,对其列混合变换进行了变型,使得逆列混合运算更适合于硬件实现。对于RSA算法,基于FPGA设计了Montgomery改进算法模乘器结构,多路复用/加法体系结构,流水线多路复用/加法体系结构。 第二部分,结合教育信息化的应用需求和实际科研项目的开发过程,成功构建了一个可信计算体系。首先建立主机的可信计算模型,提出节点重配置的原理和方法,能方便地解决密码设备的互操作性问题,特别是在教育信息化中有重要现实意义的非接触卡与CPU卡的互操作性问题。在分析当前需求和现状后,提出数字签名PKI技术与ASI生成系统相结合的PKI工作应用模式,申请者和主管部门双重主体的CA证书申请模式,设计并实现了可信学生信息服务系统和教育CA证书申请体系,即将用于学生就业网和教育信息基础资源库的建设。 第三部分,作为可信计算体系在其它领域扩展应用的一个范例,构建变电站自动化信息交换安全认证体系。在采用TCG(可信计算组织)和IEC 61850(变电站通信网络与系统)等最新国际标准的体系结构和基本方法的同时,遵循国密办“商用密码管理条例”,使用国家密码机构认可的商用密码。通过在IED(智能电子设备)中集成密码计算模块,使IED能够计算和验证数字签名,可构建变电站自动化信息交换的可信计算体系,实现信息交换过程中控制中心与变电站IED身份和信息完整性的认证。研究工作将既服务于国家制定“变电站通信网络与系统安全标准”,又能给IEC TC57 WG15(国际电工委员会第57技术委员会第15工作组)正在进行中的同类标准制定工作提供参考和探讨,具有良好的发展前景。

【Abstract】 PKI (Public Key Infrastructure),this word is explained as a kind of frame system, Users on Internet can realize the exchange of the safe information data through it, And it can content with security demand of the privacy, integrality , authenticity and undeniable. An entity can believe that mean its behavior is always towards the anticipated goal in a desirable way. The basic consider of the trusted compute is: at first structuring a trust root, the credibility of which is guaranteed by the physics security and management security. Then setting up a trust chain, from trust root, it can authenticate and trust stair from one to another, and expand this kind of trust to the whole trusted compute field. In this paper, we will combine PKI and trusted compute technology to structure trusted compute system of the exchange system of distributed information and apply to practice demand as the education, electricity, etc..This paper is divided into three parts. First part, starting from specific TPM (Trusted Platform Module) system structure requisition for cryptogram algorithm in TCG (Trusted Computing Group) standardization, then discussing the algorithm principle of typical cryptogram algorithms and optimization method of convenient hardware realize as AES and RSA ,etc, and hardware fast implementation methods of these algorithms in FPGA or DSP. Decode algorithm of AES to transform equivalently, making the circuit structure of hardware achieve of the decoding and encoding is similar, and overcoming the lack which is the realization of original algorithm decoding and encoding can only be used a few of the same circuits; In addition it change mix-column, making inverse mix-column to be more fit for the hardware achieve. For RSA algorithm, it based on FPGA to design improved algorithm Montgomery multiplier architecture, Mux/Add architecture, pipelined Mux/Add architecture.The second part, it is succeeding in structuring a trusted compute system which is combining the application demand of educational informationization and the development process of the real scientific research project. First, setting up the trusted compute model of the host computer, bringing forward the principle and method of the node re-configuration, can conveniently solve the interoperation problem of the cryptogram equipment, especially, it has the real signification in interoperation problem between the untouched card and the CPU card in the educational informationization. After analysing the present demand and current situation , putting forward PKI work application mode which combine digital signature PKI technology and ASI creating system, and CA certificate application mode that is double main body of applicant and responsible institution, having designed and realized that can trusted student’s information service system and educational CA certificate applied system ,will been used to student’s employment net and construction of basic resources bank of educational information.The third part, as trusted compute system developed and used in other fields, the example is to construct safe certification system of automatic information exchange of the substation. When using TCG and IEC 61850(Communication Networks and

  • 【网络出版投稿人】 湘潭大学
  • 【网络出版年期】2006年 12期
节点文献中: