抗量子可信计算安全支撑平台技术
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

基金项目:

国家重点研发计划 (2020YFE0200600); 国家自然科学基金 (61872343, 61802375); 中国科学院青年创新促进会资助项目


Technology of Quantum-resistant Trusted Computing Security Support Platform
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 增强出版
  • |
  • 文章评论
    摘要:

    随着科技的发展, 量子计算机大规模部署逐渐变为可能, 基于部分计算困难问题的公钥密码算法将被量子算法有效求解. 传统的可信硬件芯片如TCM/TPM等由于广泛使用了RSA、SM3、ECC等公钥密码体制, 其安全性将受到严重影响; 而绝大部分具有抗量子能力的密码算法并不适配现有TCM/TPM芯片有限的计算能力, 因此需要对抗量子可信计算平台进行重新设计. 本文针对可信计算在量子计算模型下面临的安全挑战, 分析总结了抗量子可信计算的研究现状, 改进并提出了抗量子可信计算技术体系, 并结合现有的后量子密码算法协议和可信计算软硬件技术框架, 通过在可信计算平台上移植抗量子密码算法和协议, 实现了基于TCM的抗量子可信计算安全支撑平台, 包括可信密码模块本原根设计, TCM密码库、远程证明、LDAA等抗量子可信计算扩展功能改进. 最后在可信计算仿真平台上对信任根、软件库、远程证明等抗量子TCM模块的功能和性能进行了全面测试, 结果表明平台既具有抵抗量子算法攻击的安全性, 且具有可以接受的应用性能开销.

    Abstract:

    With the development of science and technology, the deployment of large-scale quantum computers is becoming possible, and the public-key cryptographic algorithms based on some difficult problems will be solved by quantum algorithms effectively. The security of traditional trusted hardware chips such as TCM/TPM will be seriously affected due to the wide use of public-key cryptosystems such as RSA, SM3, and ECC, and most of the quantum-resistant (QR) cryptographic algorithms cannot be implemented on hardware chips with limited computational resources. Therefore, it is necessary to redesign the QR trusted computing platform. In this study, considering the security challenges faced by trusted computing in quantum computing models, we summarize the present situation of QR trusted computing research and propose a QR trusted computing technology system. Combined with the existing post-quantum cryptographic protocol and trusted computing software and hardware technology framework, we transplant the QR cryptographic algorithms and protocol on the trusted computing platform and implement a prototype system of a QR trusted computing security support platform based on TCM. The work includes the design of the primitive root key and QR extensions such as TCM cipher library, remote attestation, and LDAA. Finally, the results of function and performance tests on the emulator for the above TCM modules show that the prototype system is resistant to attacks by quantum algorithms, with acceptable application performance overhead.

    参考文献
    相似文献
    引证文献
引用本文

李为,齐兵,秦宇,冯伟.抗量子可信计算安全支撑平台技术.计算机系统应用,2022,31(5):65-74

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2021-07-02
  • 最后修改日期:2021-08-17
  • 录用日期:
  • 在线发布日期: 2022-02-25
  • 出版日期:
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京海淀区中关村南四街4号 中科院软件园区 7号楼305房间,邮政编码:100190
电话:010-62661041 传真: Email:csa (a) iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号