首页> 外文会议>Institute of Nuclear Materials Management annual meeting >A SOLUTION FOR DATA AUTHENTICATION BASED ON CRYPTOGRAPHIC TOKENS
【24h】

A SOLUTION FOR DATA AUTHENTICATION BASED ON CRYPTOGRAPHIC TOKENS

机译:基于加密令牌的数据认证解决方案

获取原文

摘要

Authentication of data sets produced by data generators is an essential IAEA security requirement for unattended and remote monitoring systems. Whilst recently developed equipment includes at the sensor level security features able to perform this function, a consistent number of older systems, especially in the NDA area, are not providing any of these functionalities. Besides, the requirement for a common approach for the different families of systems has dictated the development of an original hardware/software solution. The concept is based on the use of commercially available cryptographic tokens compliant with PKCS#11 interface format. These tokens, available from different manufacturers in the form of PCMCIA cards or USB sticks, besides performing the cryptographic functions by an internal processor, act as a secure key repository and a trusted time stamper. A simple Public Key Infrastructure with a central Certificate Authority is used for keys and certificates management. A software code has been developed to automatically process the files produced by the different collect applications and generate the digital signature through the token. The original data stream is encapsulated in a CMS envelope compliant with S/MIME specification and forwarded to the receiving node. The communication between the receiving node, usually IAEA’s HQ or Regional Offices, and the remote system is secured by means of hardware VPN devices. This paper describes the details of the solution developed as well as the results obtained so far after the first field installations.
机译:数据生成器产生的数据集的身份验证是无人值守和远程监控系统的必要原子能机构安全要求。虽然最近开发的设备包括在传感器级安全功能,能够执行此功能,但较常见的旧系统,尤其是NDA区域,不提供任何这些功能。此外,对不同系统家庭的共同方法的要求已经决定了原始硬件/软件解决方案的开发。该概念基于使用具有PKCS#11接口格式的商业上可用的加密令牌。这些标记以PCMCIA卡或USB棒形式的不同制造商提供,除了内部处理器进行加密功能外,充当安全密钥存储库和可信时间压模。具有中央证书颁发机构的简单公钥基础架构用于键和证书管理。已经开发出软件代码来自动处理不同收集应用程序生成的文件,并通过令牌生成数字签名。原始数据流封装在符合S / MIME规范的CMS信封中并转发到接收节点。接收节点(通常是IAEA的HQ或区域办事处)之间的通信,以及远程系统通过硬件VPN设备固定。本文介绍了开发的解决方案的细节以及在第一个场安装之后迄今为止所获得的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号