本文已被:浏览 825次 下载 2075次
Received:July 02, 2021 Revised:August 17, 2021
Received:July 02, 2021 Revised:August 17, 2021
中文摘要: 随着科技的发展, 量子计算机大规模部署逐渐变为可能, 基于部分计算困难问题的公钥密码算法将被量子算法有效求解. 传统的可信硬件芯片如TCM/TPM等由于广泛使用了RSA、SM3、ECC等公钥密码体制, 其安全性将受到严重影响; 而绝大部分具有抗量子能力的密码算法并不适配现有TCM/TPM芯片有限的计算能力, 因此需要对抗量子可信计算平台进行重新设计. 本文针对可信计算在量子计算模型下面临的安全挑战, 分析总结了抗量子可信计算的研究现状, 改进并提出了抗量子可信计算技术体系, 并结合现有的后量子密码算法协议和可信计算软硬件技术框架, 通过在可信计算平台上移植抗量子密码算法和协议, 实现了基于TCM的抗量子可信计算安全支撑平台, 包括可信密码模块本原根设计, TCM密码库、远程证明、LDAA等抗量子可信计算扩展功能改进. 最后在可信计算仿真平台上对信任根、软件库、远程证明等抗量子TCM模块的功能和性能进行了全面测试, 结果表明平台既具有抵抗量子算法攻击的安全性, 且具有可以接受的应用性能开销.
Abstract:With the development of science and technology, the deployment of large-scale quantum computers is becoming possible, and the public-key cryptographic algorithms based on some difficult problems will be solved by quantum algorithms effectively. The security of traditional trusted hardware chips such as TCM/TPM will be seriously affected due to the wide use of public-key cryptosystems such as RSA, SM3, and ECC, and most of the quantum-resistant (QR) cryptographic algorithms cannot be implemented on hardware chips with limited computational resources. Therefore, it is necessary to redesign the QR trusted computing platform. In this study, considering the security challenges faced by trusted computing in quantum computing models, we summarize the present situation of QR trusted computing research and propose a QR trusted computing technology system. Combined with the existing post-quantum cryptographic protocol and trusted computing software and hardware technology framework, we transplant the QR cryptographic algorithms and protocol on the trusted computing platform and implement a prototype system of a QR trusted computing security support platform based on TCM. The work includes the design of the primitive root key and QR extensions such as TCM cipher library, remote attestation, and LDAA. Finally, the results of function and performance tests on the emulator for the above TCM modules show that the prototype system is resistant to attacks by quantum algorithms, with acceptable application performance overhead.
keywords: quantum-resistant cryptographic algorithm quantum-resistant trusted cryptographic platform TPM/TCM trusted computing security support platform remote attestation information security
文章编号: 中图分类号: 文献标志码:
基金项目:国家重点研发计划 (2020YFE0200600); 国家自然科学基金 (61872343, 61802375); 中国科学院青年创新促进会资助项目
引用文本:
李为,齐兵,秦宇,冯伟.抗量子可信计算安全支撑平台技术.计算机系统应用,2022,31(5):65-74
LI Wei,QI Bing,QIN Yu,FENG Wei.Technology of Quantum-resistant Trusted Computing Security Support Platform.COMPUTER SYSTEMS APPLICATIONS,2022,31(5):65-74
李为,齐兵,秦宇,冯伟.抗量子可信计算安全支撑平台技术.计算机系统应用,2022,31(5):65-74
LI Wei,QI Bing,QIN Yu,FENG Wei.Technology of Quantum-resistant Trusted Computing Security Support Platform.COMPUTER SYSTEMS APPLICATIONS,2022,31(5):65-74