1673-159X

CN 51-1686/N

基于时间特性的容侵密钥管理研究及进展

Study on Intrusion Resilient Key Management with Time Properties and Its Advance

  • 摘要: 密钥是密码系统安全的核心, 不可避免地会受到敌手的重点攻击。这就要求密钥管理系统具有自我诊断、恢复和重构的自适应容侵能力。作者提出的基于时间特性的密钥容侵管理研究, 重点考虑在各类密码应用中密钥(公钥、私钥、子密钥、密钥链等) 随着时间变化而演化的算法、协议设计, 进行相应体制或系统的安全性和有效性分析, 以更好地在具有攻击敌手的环境下, 提高密钥的容侵与生存能力, 更好地保障基于密码的应用技术安全。本文对具有时间特性的密钥容侵管理的基本模型、前向安全签名的密钥演化、主动秘密共享方案的子密钥演化、具有自愈能力的高效时变密钥的生成与分配等四个方面的研究内容进行了分析, 并综述了国内外相关研究的进展, 进而针对这些研究内容提出了可进一步研究的具体问题和技术路线。

     

    Abstract: Key management is the security core of cryptosystem; it will inevitably be the focus of attacks by adversary. This requires key management system with self-diagnosis, rehabilitation and reconstruction of the self-adaptive intrusion resilient capabilities. This paper presents a time-based intrusion resilient key management issue, with emphasis to consider the application of various types of keys (public key, private key, sub-key, key chain, etc.) changing over time, evolutionary algorithm, protocol design, and make the cryptographic system safer and more effective to better protect the security of cipher-based application technology. The research contents are analyzed in four areas: the basic key management model of time-based intrusion resilient key management, a forward-secure signature key evolution, proactive secret sharing scheme of the sub-key evolution, efficient self-healing capability with time-varying key generation and distribution. Some specific key issues and technical routes for further research on these contents are proposed.

     

/

返回文章
返回