摘要
云计算已经成为当前计算机技术的研究热点,经过验证,可信计算技术可以有效地解决云计算环境下数据传输的安全性。但是,由于负责提供密码服务的可信密码模块是一枚SOC芯片,其处理速度有限,不能适应云计算环境下频繁数据传输和多用户连接的情况。论文提出了一种云计算环境下的可信密码模块密码功能授权代理的实现方法,通过一级密钥认证授权和保护一级密钥的方法,将可信密码模块的加解密和签名功能代理到每个虚拟机中,每个虚拟机当中能够拥有一个轻量级的密码代理模块完成相关密码功能,提高了整个平台的密码业务处理效率。
It is proved that trusted computing could improve the security of the cloud computing platform. However, in trusted computing technology, the Trusted Cryptographic Module(TCM), which provides basic cryptographic functions, is a SOC chip, whose data process is not high-speed, and is not fit to handle the frequent data transfer and multi-user connection. A method to delegate the TCM cryptographic functions in cloud computing environment is proposed in this paper. In the method, the encryption, decryption and signing functions of TCM are delegated to TCM cryptographic delegation modules in virtual machines. In this way, each virtual machine has a TCM cryptographic delegation module to provide the same crypto- graphic functions as what TCM provides, and it improves the efficiency of the cryptographic process of the cloud computing platform.
出处
《计算机与数字工程》
2014年第5期855-858,共4页
Computer & Digital Engineering
关键词
云计算
可信密码模块
密码功能授权代理
cloud computing, trusted cryptographic module, cryptographic functions delegation