首页> 外文会议>International Conference on Field Programmable Logic and Applications >FPGA based Rekeying for cryptographic key management in Storage Area Network
【24h】

FPGA based Rekeying for cryptographic key management in Storage Area Network

机译:基于FPGA的密钥更新,用于存储区域网络中的密钥管理

获取原文

摘要

Rekeying process plays an important role in secure large-scale Storage Area Network (SAN) applications. Software based Rekeying management could not completely prevent sensitive information leakage from theoretical and physical attacks. Traditional Rekeying process will suffer from decrypting the large data using the old key and encrypting it with the new key. In order to solve these problems, we proposed a FPGA based flexible and low-cost rekeying management to improve the security and reduce the processing time. In the proposed method, enveloping key is defined and added into the rekeying process to protect the real private key and the user's access key. During the rekeying process, the user's access key is substituted and send back to the user instead of real private key. In order to save the transformation time between the Policies Key Control (software) and key management (hardware), we proposed index extraction solution to shorten bit width of transformation from 256-bit to only 32-bit. Experimental results show that our proposed method only takes up 1.099 ms for rekeying process compared with the existing design with 3.91 ms execution time.
机译:密钥更新过程在安全的大规模存储区域网络(SAN)应用程序中起着重要作用。基于软件的密钥更新管理不能完全防止敏感信息从理论和物理攻击中泄漏。传统的密钥更新过程将遭受使用旧密钥解密大数据并使用新密钥加密大数据的困扰。为了解决这些问题,我们提出了一种基于FPGA的灵活,低成本的密钥更新管理,以提高安全性并减少处理时间。在所提出的方法中,定义了封装密钥并将其添加到重新生成密钥的过程中,以保护真实私钥和用户的访问密钥。在重新键入密钥的过程中,将替换用户的访问密钥,并将其发送回用户,而不是发送回真实私钥。为了节省策略密钥控制(软件)和密钥管理(硬件)之间的转换时间,我们提出了索引提取解决方案,以将转换的位宽度从256位缩短到仅32位。实验结果表明,与现有设计的执行时间为3.91 ms相比,本文提出的方法仅需要1.099 ms的密钥更新过程。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号