基于标识密码的双向认证的安全启动协议
DOI:
CSTR:
作者:
作者单位:

中国电子科技集团公司第五十四研究所

作者简介:

通讯作者:

中图分类号:

基金项目:

中国电子科技集团公司第五十四研究所项目研究发展基金(SXX22107X042)


A Secure Boot Protocol for Bidirectional Authentication Based on IBC
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    传统安全启动(Secure boot)方案的认证环节是基于公钥基础设施(Public Key Infrastructure,PKI)体制实现,在设备数量剧增的情况下,证书的管理会增加系统复杂性,认证过程仅实现了单向认证,安全性不足。此外,由于选择了链式信任链,导致了在启动过程中的信任传递损失较大。针对上述问题,本文提出了一种基于标识密码(Identity-Based Encryption,IBC)体制的Secure boot方案,即IBCEB方案。该方案使用了IBC体制的国家标准SM9算法作为实现方法,实现了无证书的双向认证协议,并对信任链模型进行了优化,降低了信任传递的损失。在ZC706评估板上进行了测试,测试结果表明,设备在双向认证后成功启动,提高了系统的安全性。

    Abstract:

    The authentication process of traditional Secure Boot schemes is based on the Public Key Infrastructure (PKI) system. With the sharp increase in the number of devices, certificate management will increase system complexity, and the authentication process only achieves one-way authentication, resulting in insufficient security. In addition, because the chained chain of trust is selected, the loss of trust transmission during the startup process is large. In response to the above issues, this article proposes a Secure Boot scheme based on the Identity Based Encryption (IBC) system, namely the IBCEB scheme. The scheme uses the national standard SM9 algorithm of IBC system as the implementation method, implements the certificateless two-way authentication protocol, optimizes the Chain of trust model, and reduces the loss of trust transmission. Tests were conducted on the ZC706 evaluation board, and the test results showed that the device successfully started after bidirectional authentication, improving the system"s security.

    参考文献
    相似文献
    引证文献
引用本文

冯云龙,张宏科,刘林海.基于标识密码的双向认证的安全启动协议计算机测量与控制[J].,2024,32(4):287-292.

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2023-09-08
  • 最后修改日期:2023-10-25
  • 录用日期:2023-10-26
  • 在线发布日期: 2024-04-29
  • 出版日期:
文章二维码