首页|基于标识密码的双向认证的安全启动协议

基于标识密码的双向认证的安全启动协议

扫码查看
传统安全启动方案的认证环节是基于PKI体制实现,在设备数量剧增的情况下,证书的管理会增加系统复杂性,认证过程仅实现了单向认证,安全性不足;此外,由于选择了链式信任链,导致了在启动过程中的信任传递损失较大;针对上述问题,文章提出了一种基于IBC的Secure boot方案,即IBCEB方案;该方案使用了IBC体制的国家标准SM9算法作为实现方法,实现了无证书的双向认证协议,并对信任链模型进行了优化,降低了信任传递的损失;在ZC706评估板上进行了测试,测试结果表明,设备在双向认证后成功启动,提高了系统的安全性。
A Secure Boot Protocol for Bidirectional Authentication Based on IBC
The authentication process of traditional secure boot schemes is based on the Public Key Infrastructure(PKI)system.With the sharp increase in the number of devices,certificate management will increase system complexity,and the authentication process only achieves one-way authentication,resulting in insufficient security.In addition,because of the selection of a chain-based trust chain,there is a significant loss of trust transmission during the startup process.In response to the above issues,a secure boot scheme based on the identity-based encryption(IBC)system is proposed,namely the IBCEB scheme.The scheme uses the national standard SM9 algorithm of IBC system as an implementation method,implements the uncertified bidirectional authentication protocol,optimizes the model of trust chain,and reduces the loss of trust transmission.Test on the ZC706 evaluation board,the test results show that the device successfully starts after the bidirectional authentication,improving the security of the system.

Secure bootIBCSM9no certificationbidirectional authentication

冯云龙、张宏科、刘林海

展开 >

中国电子科技集团公司第54研究所,石家庄 050081

Secure boot IBC SM9 无证书 双向认证

中国电子科技集团公司第五十四研究所项目研究发展基金

SXX22107X042

2024

计算机测量与控制
中国计算机自动测量与控制技术协会

计算机测量与控制

CSTPCD
影响因子:0.546
ISSN:1671-4598
年,卷(期):2024.32(4)
  • 24