节点文献

基于Fabric联盟链的量子安全PKI应用研究与实现

Application Research and Implementation of Quantum Secure PKI Based on Hyperledger Fabric

【作者】 周旭;

【导师】 向宏;

【作者基本信息】 重庆大学 , 工程(软件工程)(专业学位), 2022, 硕士

【摘要】 公钥密码学是网络空间信任链建立的基石,但近年来量子计算的快速发展严重威胁了ECDSA、RSA等经典公钥密码算法的安全性。研究抵抗量子计算威胁的密码学前沿分支——后量子密码学日益受到重视。美国国家标准与技术研究院NIST于2016年启动后量子密码算法标准化工作,目前该标准化工作已进入第三轮,共入围6个基于多个理论的签名算法,根据美国白宫国家安全备忘录该标准化工作将于2024年完成。随着后量子密码标准化的推进,后量子密码迁移工作成为密码应用与工程研究的热点。公钥基础设施(Public Key Infrastructure,PKI)是公钥密码算法的典型应用,也是各类重要信息系统后量子密码迁移工作的核心之一。Hyperledger Fabric联盟链以公钥基础设施为基础建立了Fabric网络信任机制,使用签名算法实现交易、背书等区块链核心功能,故公钥密码算法的安全性对其尤为重要。因此,本文以应用广泛的Hyper-ledger Fabric联盟链为研究场景,进行Fabric联盟链PKI的后量子密码迁移研究,探索如何建立实现量子安全的Fabric联盟链PKI。本文首先分析了Fabric信任网络的建立过程,描述了Fabric信任网络中受到量子计算威胁的组件;然后使用开放量子安全的liboqs开源库,从算法参数集选择、编程语言、Fabric核心密码模块和应用层四个方面设计并实现了量子安全的Fabric公钥基础设施方案;最后,本文还比较了方案中不同场景下各种后量子签名算法的性能效率,对各签名算法进行综合评价,为后量子密码迁移工作的算法选择提供参考。实验结果表明在Fabric量子安全公钥基础设施方案中,Dilithium、Falcon等后量子公钥密码算法最为理想,算法效率优越,通信效率均衡;Rainbow算法的小签名具有潜在的优势区间;Picnic、SPHINCS+则表现欠佳。

【Abstract】 Public key cryptography lies in the basis of trust chain in cyberspace.But in recent years,the development of quantum computing has seriously threatened the security of classical public key cryptography algorithms such as ECDSA and RSA.Post-quantum cryptography(PQC),a frontier branch of cryptography which could resist the threat of quantum computing,is drawing more and more attention.NIST,the National Institute of Standards and Technology in the United States,started the standardization of PQC algorithms in 2016.Currently,this work has entered its third round,and 6 signature algorithms based on different theories have been shortlisted.According to the White House’s National Security Memorandum,this work will be completed by 2024.With the advancement of this work,PQC migration has also become a hot topic in cryptography application and engineering research.Public key infrastructure(PKI)is a typical application of public key cryptography,lying at the core of various important information systems’ PQC migration.Hyperledger Fabric establishes its network trust mechanism based on PKI and uses signature algorithm to realize blockchain core functions such as transaction and endorsement.Therefore,the security of public key cryptography algorithm is particularly important for Fabric.This paper thus takes Fabric as the research scenario to study PQC migration of PKI and explore how to establish PKI with the aim of achieving quantum security.This paper firstly analyzes the establishment of Fabric trust network and describes components threatened by quantum computing.Then,a quantum secure Fabric PKI scheme is designed and implemented from four aspects: algorithm parameter set selection,programming language,Fabric core cryptographic module and application layer,by using Liboqs.Finally,the performance and efficiency of each signature algorithm in different scenarios are compared,and the comprehensive evaluation of each signature algorithm is carried out to provide reference for algorithm selection of PQC migration.The experimental results show that in the scheme,Dilithium and Falcon are the most ideal post-quantum algorithms,with superior algorithm efficiency and balanced communication efficiency.The small signature of Rainbow also has potential advantage scenarios.The performance of Picnic and SPHINCS+ is mediocre.

  • 【网络出版投稿人】 重庆大学
  • 【网络出版年期】2024年 11期
  • 【分类号】TN918.4;O413
节点文献中: