您的位置: 专家智库 > >

国家自然科学基金(61303024)

作品数:6 被引量:19H指数:3
相关作者:李晶何凡张立强应时石翔更多>>
相关机构:武汉大学湖北省电力公司武汉理工大学更多>>
发文基金:国家自然科学基金国家重点基础研究发展计划江苏省自然科学基金更多>>
相关领域:自动化与计算机技术电子电信更多>>

文献类型

  • 4篇中文期刊文章

领域

  • 3篇自动化与计算...
  • 1篇电子电信

主题

  • 1篇虚拟机
  • 1篇远程
  • 1篇远程证明
  • 1篇访问控制
  • 1篇NEW
  • 1篇POLYNO...
  • 1篇PROBLE...
  • 1篇STAR
  • 1篇TRUST_...
  • 1篇TRUSTE...
  • 1篇WEB服务安...
  • 1篇ABILIT...
  • 1篇INFORM...
  • 1篇KERBER...
  • 1篇MP
  • 1篇WEB服务
  • 1篇MULTIV...
  • 1篇IAAS
  • 1篇MORPHI...
  • 1篇STYLE

机构

  • 2篇武汉大学
  • 1篇教育部
  • 1篇武汉理工大学
  • 1篇湖北省电力公...

作者

  • 1篇王鹃
  • 1篇王涛
  • 1篇应时
  • 1篇张立强
  • 1篇严飞
  • 1篇何凡
  • 1篇李晶
  • 1篇王庆飞
  • 1篇石翔

传媒

  • 2篇武汉大学学报...
  • 1篇Wuhan ...
  • 1篇Tsingh...

年份

  • 1篇2017
  • 2篇2016
  • 1篇2014
6 条 记 录,以下是 1-4
排序方式:
IaaS下虚拟机的安全存储和可信启动被引量:3
2014年
针对大多数现有技术主要依据可信硬件来保护虚拟机(VM,virtual machine)运行平台的安全,而缺乏对VM安全存储和可信启动保护的问题,提出了一种解决在云平台基础设施服务策略(IaaS,Infrastructure as a Service)下VM的安全存储和可信启动(SSTL,secure storage and trusted launch)方案.根据可信平台模块(TPM,trusted platform module)的一些核心功能,分别从VM镜像加解密、VM宿主平台信息的远程证明和VM度量机制来保证VM存储安全、VM运行环境的安全以及VM可信启动.实验测试与分析表明该系统能够防止非授权启动VM,并能检测针对VM的系统服务描述符表(SSDT,system services descriptor table)以及Kernel Module等系统核心模块攻击.并且对原有系统的性能损耗在允许范围之内,不影响用户的正常使用.
王庆飞严飞王鹃王涛石翔
关键词:虚拟机远程证明
一种基于Kerberos扩展的Web服务安全框架被引量:8
2017年
Web服务安全问题集中表现在信任建立、端到端消息安全保障以及资源访问控制等方面.传统的Web安全框架如Atlassian Seraph和Apache Shiro无法同时解决消息安全保护和跨域访问控制的问题.本文提出并实现一种基于Kerberos的Web服务安全框架——KBW2SF,它包括用户认证、消息安全通信、服务访问控制三个核心功能.用户认证使用Kerberos作为底层协议在服务请求发和提供方之间建立信任关系;安全通信使用WSSecurity规范及Kerberos票据中的密钥保证消息端到端的完整性和机密性;服务访问控制基于Kerberos票据中的用户角色信息,由服务提供方对来访用户进行角色映射(跨域访问)和权限鉴定,以此保护服务资源不被非法或者低权限用户访问.同时,KBW2SF引入缓存管理机制提高应用效率,降低安全机制对Web服务应用的影响程度.通过应用场景的实验分析,该框架不但能够有效解决Web服务消息的安全性以及跨域访问控制问题,而且具有较高的效率,具备一定的实际应用价值.
张立强何凡叶卫军应时李晶
关键词:WEB服务WEB服务安全KERBEROS访问控制
A Star-Style Trust Model with the Ability of Data Recovery for Trusted Computing Platform
2016年
Varieties of trusted computing products usually follow the mechanism of liner-style chain of trust according to the specifications of TCG.The distinct advantage is that the compatibility with the existing computing platform is preferable,while the shortcomings are obvious simultaneously.A new star-style trust model with the ability of data recovery is proposed in this paper.The model can enhance the hardware-based root of trust in platform measurement,reduce the loss of trust during transfer process,extend the border of trust flexibly,and have the ability of data backup and recovery.The security and reliability of system is much more improved.It is proved that the star-style trust model is much better than the liner-style trust model in trust transfer and boundary extending etc.using formal methods in this paper.We illuminate the design and implementation of a kind of trusted PDA acting on star-style trust model.
CHEN LuZHANG HuanguoZHOU QingZHANG Liqiang
New Public-Key Cryptosystem Based on the Morphism of Polynomials Problem被引量:1
2016年
During the last two decades, there has been intensive and fast development in Multivariate Public Key Cryptography (MPKC), which is considered to be an important candidate for post-quantum cryptography. However, it is universally regarded as a difficult task, as in the Knapsack cryptosystems, to design a secure MPKC scheme (especially an encryption scheme) employing the existing trapdoor construction. In this paper, we propose a new key-exchange scheme and an MPKC scheme based on the Morphism of Polynomials (MP) problem. The security of the proposed schemes is provably reducible to the conjectured intractability of a new difficult problem, namely the Decisional Multivariate Diffie-Hellman (DMDH) problem derived from the MP problem. The proposed key agreement is one of several non-number-theory-based protocols, and is a candidate for use in the post-quantum era. More importantly, by slightly modifying the protocol, we offer an original approach to designing a secure MPKC scheme. Furthermore, the proposed encryption scheme achieves a good tradeoff between security and efficiency, and seems competitive with traditional MPKC schemes.
Houzhen WangHuanguo ZhangShaowu MaoWanqing WuLiqiang Zhang
共1页<1>
聚类工具0