• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2016, Vol. 38 ›› Issue (02): 249-254.

• 论文 • 上一篇    下一篇

一种基于软硬件协同的程序安全关键数据动态保护机制

岳虹1,王蕾2,邓宇2,刘磊3   

  1. (1.61070部队,福建 福州 350001;2.国防科学技术大学计算机学院,湖南 长沙 410073;
    3.信息保障技术重点实验室,北京 100084)
  • 收稿日期:2015-09-15 修回日期:2015-11-18 出版日期:2016-02-25 发布日期:2016-02-25
  • 基金资助:

    国家自然科学基金(61402501)

A dynamic mechanism of critical data protection
based on hardwaresoftware cooperation       

YUE Hong1,WANG Lei2,DENG Yu2,LIU Lei3   

  1. (1.Troop 61070,Fuzhou 350001;2.College of Computer,National University of Defense Technology,Changsha 410073;
    3.Key Laboratory of Information Assurance Technology,Beijing 100084,China)
  • Received:2015-09-15 Revised:2015-11-18 Online:2016-02-25 Published:2016-02-25

摘要:

针对内存和片外总线可能遭受的物理攻击,为保护内存数据安全,提出了一种基于软硬件协同的程序安全关键数据动态保护机制,提取用户定义的安全关键数据放置于安全区域,并且采用动态完整性验证的方式来判断其是否遭到篡改。与传统的程序内存数据保护机制相比,该机制具备能够预防基于硬件及软件的攻击、节约片上和片外存储空间、完整性运算量小、安全效能高等优点。

关键词: 程序, 安全关键数据, 软硬件协同, 动态保护

Abstract:

In response to the physical attacks on the internal storage and offchip bus so as to ensure the safety of stored data, we propose a dynamic mechanism of critical data protection based on hardwaresoftware cooperation, which can extract userdefined key safety data, store them into the key safety area, and adopt dynamic integrity verification to examine whether the data has been tampered. Compared with the traditional way of protecting program memory data, the proposed method has the advantage of preventing attacks on the hardware and software, saving onchip and offchip memory, reducing the processing time and enhancing the safety performance.

Key words: program;critical safety data;hardware-software cooperation;dynamic protection