基于SM4形式化验证的工业互联网数据安全技术研究

Zhenya Chen, Yushen Deng, Ming Yang, Chao Mu, Shuo Xu, Fazong Wu
{"title":"基于SM4形式化验证的工业互联网数据安全技术研究","authors":"Zhenya Chen, Yushen Deng, Ming Yang, Chao Mu, Shuo Xu, Fazong Wu","doi":"10.1109/EPCE58798.2023.00039","DOIUrl":null,"url":null,"abstract":"Industrial Internet promotes the transformation of industrial platform from business system driven to data driven through the flow of industrial data between massive multi-source equipment and heterogeneous systems. The data flow of industrial Internet involves the interactive transmission of a large number of key sensitive information between enterprises. Coupled with its inherent openness and heterogeneity, it is facing serious security challenges such as sensitive data leakage and integrity destruction. Cryptography technology is one of the important methods to ensure data security. Among them, the national cryptographic algorithm can meet the requirements of security, autonomy and controllability of Chinese industrial Internet data, and avoid the risk of \"backdoor\" when the current mainstream international cryptography algorithm protects the key sensitive data. However, there are still security threats such as memory leakage and time-side channel attack which cause the invalidity of encryption mechanism when the national cryptographic algorithm is deployed in industrial Internet system. Formal verification method is an important method to verify the security and reliability of cryptographic algorithms. Existing researches have designed a variety of formal verification mechanisms for the underlying cryptographic algorithms of some structures and protocols, but the research on formal verification for national cryptographic algorithm is still in a blank stage. This paper proposes a formal verification method of SM4 cryptographic algorithm based on programming framework F*, which can ensure the memory security and resist the time-side channel attacks during the implementation of the algorithm. And the method can reduce the security risks, when the national cryptographic algorithm is deployed in the industrial internet.","PeriodicalId":355442,"journal":{"name":"2023 2nd Asia Conference on Electrical, Power and Computer Engineering (EPCE)","volume":"185 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-04-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Research on Industrial Internet Data Security Technology based on Formal Verification of SM4\",\"authors\":\"Zhenya Chen, Yushen Deng, Ming Yang, Chao Mu, Shuo Xu, Fazong Wu\",\"doi\":\"10.1109/EPCE58798.2023.00039\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Industrial Internet promotes the transformation of industrial platform from business system driven to data driven through the flow of industrial data between massive multi-source equipment and heterogeneous systems. The data flow of industrial Internet involves the interactive transmission of a large number of key sensitive information between enterprises. Coupled with its inherent openness and heterogeneity, it is facing serious security challenges such as sensitive data leakage and integrity destruction. Cryptography technology is one of the important methods to ensure data security. Among them, the national cryptographic algorithm can meet the requirements of security, autonomy and controllability of Chinese industrial Internet data, and avoid the risk of \\\"backdoor\\\" when the current mainstream international cryptography algorithm protects the key sensitive data. However, there are still security threats such as memory leakage and time-side channel attack which cause the invalidity of encryption mechanism when the national cryptographic algorithm is deployed in industrial Internet system. Formal verification method is an important method to verify the security and reliability of cryptographic algorithms. Existing researches have designed a variety of formal verification mechanisms for the underlying cryptographic algorithms of some structures and protocols, but the research on formal verification for national cryptographic algorithm is still in a blank stage. This paper proposes a formal verification method of SM4 cryptographic algorithm based on programming framework F*, which can ensure the memory security and resist the time-side channel attacks during the implementation of the algorithm. And the method can reduce the security risks, when the national cryptographic algorithm is deployed in the industrial internet.\",\"PeriodicalId\":355442,\"journal\":{\"name\":\"2023 2nd Asia Conference on Electrical, Power and Computer Engineering (EPCE)\",\"volume\":\"185 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2023-04-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2023 2nd Asia Conference on Electrical, Power and Computer Engineering (EPCE)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/EPCE58798.2023.00039\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 2nd Asia Conference on Electrical, Power and Computer Engineering (EPCE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/EPCE58798.2023.00039","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

摘要

工业互联网通过海量多源设备和异构系统之间的工业数据流动,推动工业平台由业务系统驱动向数据驱动转变。工业互联网的数据流涉及企业之间大量关键敏感信息的交互传输。再加上其固有的开放性和异构性,它面临着敏感数据泄露和完整性破坏等严峻的安全挑战。加密技术是保证数据安全的重要手段之一。其中,国家加密算法能够满足中国工业互联网数据的安全性、自主性和可控性要求,避免了当前国际主流加密算法在保护关键敏感数据时出现“后门”的风险。然而,在工业互联网系统中部署国家加密算法时,仍然存在内存泄漏、时侧信道攻击等安全威胁,导致加密机制失效。形式验证方法是验证密码算法安全性和可靠性的重要方法。现有的研究已经为一些结构和协议的底层密码算法设计了各种形式的验证机制,但是对于国家密码算法的形式验证的研究还处于空白阶段。本文提出了一种基于编程框架F*的SM4密码算法的形式化验证方法,该方法在算法实现过程中既能保证内存安全性,又能抵抗时侧信道攻击。当国家密码算法部署在工业互联网中时,该方法可以降低安全风险。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Research on Industrial Internet Data Security Technology based on Formal Verification of SM4
Industrial Internet promotes the transformation of industrial platform from business system driven to data driven through the flow of industrial data between massive multi-source equipment and heterogeneous systems. The data flow of industrial Internet involves the interactive transmission of a large number of key sensitive information between enterprises. Coupled with its inherent openness and heterogeneity, it is facing serious security challenges such as sensitive data leakage and integrity destruction. Cryptography technology is one of the important methods to ensure data security. Among them, the national cryptographic algorithm can meet the requirements of security, autonomy and controllability of Chinese industrial Internet data, and avoid the risk of "backdoor" when the current mainstream international cryptography algorithm protects the key sensitive data. However, there are still security threats such as memory leakage and time-side channel attack which cause the invalidity of encryption mechanism when the national cryptographic algorithm is deployed in industrial Internet system. Formal verification method is an important method to verify the security and reliability of cryptographic algorithms. Existing researches have designed a variety of formal verification mechanisms for the underlying cryptographic algorithms of some structures and protocols, but the research on formal verification for national cryptographic algorithm is still in a blank stage. This paper proposes a formal verification method of SM4 cryptographic algorithm based on programming framework F*, which can ensure the memory security and resist the time-side channel attacks during the implementation of the algorithm. And the method can reduce the security risks, when the national cryptographic algorithm is deployed in the industrial internet.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信