首页 | 本学科首页   官方微博 | 高级检索  
     

具有主动免疫能力的电力终端内嵌入式组件解决方案
引用本文:于杨,姚浩,习伟,秦宇,赵世军.具有主动免疫能力的电力终端内嵌入式组件解决方案[J].南方电网技术,2020,14(1):65-73.
作者姓名:于杨  姚浩  习伟  秦宇  赵世军
作者单位:南方电网科学研究院,广州510663;南方电网数字电网研究院,广州510663;中国科学院软件研究所,北京,100084
基金项目:国家重点研发计划资助(2018YFB0904900,2018YFB0904903)。
摘    要:智能电网发展迅速,现有的通过物理隔离来保护电力系统终端的防护手段已经不足以应对一些新的威胁。本文提出了一种具有主动免疫能力的电力终端内嵌入式组件解决方案,为用户提供可信身份认证、可信存储、可信度量和可信报告的完整可信的计算环境。以信任链为核心,以高安全国密算法模块作为可信根,构建了覆盖安全启动、安全分区隔离、信任链传递机制和动态度量机制的主动免疫可信计算技术方案,并对该方案进行了原型实现。实验证明了该方案可以抵御恶意软件注入及破坏安全启动的攻击,并且具有良好的效率。

关 键 词:主动免疫  嵌入式系统  安全启动  可信安全芯片  可信执行环境

Solution Scheme of Embedded Component with Active Immunity for Electric Power Terminals
YU Yang,YAO Hao,XI Wei,QIN Yu,ZHAO Shijun.Solution Scheme of Embedded Component with Active Immunity for Electric Power Terminals[J].Southern Power System Technology,2020,14(1):65-73.
Authors:YU Yang  YAO Hao  XI Wei  QIN Yu  ZHAO Shijun
Affiliation:(Electric Power Research Institute,CSG,Guangzhou 510663,China;Digital Grid Research Institute,CSG,Guangzhou 510663,China;Institute of Software,Chinese Academy of Sciences,Beijing100084,China)
Abstract:With the development of smart grids,the existing protection for power system terminals through physical isolation is not enough to deal with new threats.In this paper an embedded component solution with active immunity is proposed,which provides users with a complete trusted computing environment for trusted identity authentication,trusted storage,trusted metrics and trusted reporting.With the high-security national cryptography algorithm module as the root of trust,an active immune trusted computing technology solution covering secure boot,secure partition isolation,trust chain delivery mechanism and dynamic measurement mechanism is constructed.The proposed solution and the experiments prove that the solution can efficiently resist malware injection and secure boot attack.
Keywords:active immunity  embedded system  security boot  security chip of trust  trusted execution environment
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号