摘要
随着可调加密模式的引入,整盘加密相对于文件级加密提供了更优化的抗攻击能力,既能保持加密数据的机密性,还能实现对磁盘结构元数据的隐蔽。然而,现有的磁盘加密方式在拓宽机密数据覆盖的同时也加深了对磁盘主密钥的依赖。被单个密钥所加密的数据量提高后,就引出了密钥管理的难题:怎样使密钥的获取便利与如何减小计算和存储负荷。为解决这类问题,提出一个基于逻辑口令锁的整盘加密方案,并对其进行安全性和性能分析。分析发现,该方案具有比现有磁盘加密方式更高的安全性与效率。
Full disk encryption,which not only holds the secret of encrypted data but also conceals the meta data of disk structure,can give the more optimized defense against attack than file-system-level encryption as the tweakable enciphering mode introduced.However,the current disk encryption will raise dependence on the master key while broadening the coverage of confidential data,because the mount of data encrypted by single key will also be increased,Thus it causes the key distribution problems whether the master key can be derived conveniently and how the workload of computation and storage will be reduced.To solve this,a scheme of full disk encryption based on slide password lock was described and an analysis of environment and efficiency on the scheme was given.
出处
《计算机科学》
CSCD
北大核心
2010年第10期95-97,109,共4页
Computer Science
基金
国家自然科学基金(No.60803151)资助
关键词
计算机安全
磁盘加密
可调分组密码
密钥管理
Computer security
Full disk encryption
Tweakable block cipher
Key management