首页> 外文期刊>Future generation computer systems >Bus and memory protection through chain-generated and tree-verified Ⅳ for multiprocessors systems
【24h】

Bus and memory protection through chain-generated and tree-verified Ⅳ for multiprocessors systems

机译:通过链生成和树验证的Ⅳ为多处理器系统提供总线和内存保护

获取原文
获取原文并翻译 | 示例
       

摘要

Protecting information against malicious disclosure and tampering is crucial to secure/trusted computing. This paper proposes a method to protect the off-chip data in symmetric shared memory multiprocessors systems. Existing techniques have flaws in either security or performance, which are mainly due to their management of cipher parameter and their deployment of hash tree. The proposed method provides data encryption and authentication through constructing a pair of (data, MAC, Ⅳ) for each data block to be protected, which can ensure data unbroken so far as the cryptographic parameter of Ⅳ is un-tampered. To solve the problem of Ⅳ management, Ⅳ is generated through chaining all the history data transferred on the system bus in time sequence; to solve the problem of hash tree deployment, it restricts hash tree into MCH and forwards IV to the processor through a safe channel. As for security, it can resist any attacks, including the intractable message-drop attack on bus and replay attack on memory. As for performance, it connects bus protection with memory protection smoothly by removing any additional data re-encryption/re-authentication from the data path, and it also eliminates additional message traffic caused by synchronizing a hash tree authentication result among processors. The experiment simulations inspect its specific realization, and the performance results show that it is an efficient way to achieve data protection for a shared memory multiprocessor system.
机译:保护信息免遭恶意披露和篡改对于安全/可信计算至关重要。本文提出了一种在对称共享存储器多处理器系统中保护片外数据的方法。现有技术在安全性或性能上都有缺陷,这主要是由于它们对密码参数的管理以及对哈希树的部署。所提出的方法通过为每个要保护的数据块构造一对(数据,MAC,Ⅳ)来提供数据加密和身份验证,只要Ⅳ的密码参数不受篡改,就可以确保数据不被破坏。为了解决Ⅳ管理的问题,Ⅳ是通过按时间顺序链接在系统总线上传输的所有历史数据生成的;为了解决散列树部署的问题,它将散列树限制在MCH中,并通过安全通道将IV转发给处理器。至于安全性,它可以抵抗任何攻击,包括对总线的棘手消息丢弃攻击和对内存的重播攻击。在性能方面,它通过消除数据路径中的任何其他数据重新加密/重新身份验证,将总线保护与内存保护平滑地连接在一起,并且还消除了由于在处理器之间同步哈希树身份验证结果而导致的其他消息流量。实验仿真检验了其具体实现,性能结果表明,它是共享内存多处理器系统实现数据保护的有效方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号