Method for safe improvement of TLS protocol processing based on CPU space-time isolation mechanism

A protocol processing and protocol security technology, which is applied in secure communication devices, user identity/authority verification, digital transmission systems, etc., can solve problems such as insufficient independence and lack of platform authentication, and achieve the effect of solving potential safety hazards

Active Publication Date: 2017-04-26
中软信息系统工程有限公司
View PDF3 Cites 14 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0005] In order to solve the above problems, the present invention designs a method for improving the security of TLS protocol processing based on the CPU space-time isolation mechanism. By safely improving the processing flow of the TLS handshake protocol, the lack of TLS in the integrity authentication of the communication platform is expanded, and the solution is effectively solved. Eliminate the potential safety hazards caused by the high level of TLS protocol implementation, insufficient independence, lack of platform authentication, etc., and improve the security of both computer communication parties in terms of data encryption transmission and platform identity authentication

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method for safe improvement of TLS protocol processing based on CPU space-time isolation mechanism

Examples

Experimental program
Comparison scheme
Effect test

Embodiment 1

[0043] A method for improving the security of TLS protocol processing based on the CPU space-time isolation mechanism, the specific operations are as follows:

[0044] First, build a trusted execution environment of the TLS protocol security proxy component, that is, the security kernel; the security kernel provides basic memory management, task scheduling, interrupt handling, cryptographic algorithm services, key management, and the core framework of TEE sessions, and is isolated through CPU time and space. Features, running on the CPU security core; at the same time, a TLS protocol security proxy module, certificate management module, and platform information management module should be provided in a feasible execution environment;

[0045] Secondly, build a general operating environment for the TLS protocol processing module to run, that is, the general operating system kernel, which runs on the common core of the CPU and provides the TLS protocol processing module;

[0046...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention discloses a method for the safe improvement of TLS protocol processing based on a CPU space-time isolation mechanism. The method includes, at first, constructing a trusted execution environment for a TLS protocol security agent assembly, that is, a security kernel; secondly, constructing a common running environment for the running of a TLS protocol processing module, that is, a general operating system kernel; and at the end, constructing a security monitor being responsible for the context switching between two running environments and running in the CPU security kernel. The method is advantageous in that the processing flow of a TLS handshake protocol is safely improved, the deficiency of the TLS in the communication platform integrity authentication aspect is expanded, so that the security hidden troubles caused by the high realization level, insufficient independence, and missed platform authentication of the TLS protocol are effectively solved, and the security of data encryption transmission and platform identity authentication of the two parties of the computer communication is improved.

Description

technical field [0001] The invention relates to a safety improvement of the TLS protocol, in particular to a method for improving the safety of the TLS protocol processing based on a CPU space-time isolation mechanism, and belongs to the field of safety improvement of the TLS protocol. Background technique [0002] With the continuous development of information technology and the popularization of the application of national economy and national defense military information technology, more and more users use the network for data communication, especially in the field of e-commerce, which needs to transmit a large amount of sensitive information in the transaction process . Under such circumstances, how to ensure the integrity and confidentiality of data transmission, as well as the authenticity and authenticity of platform interaction, are crucial to software providers and users involved in computer security communication services. At present, secure communication software...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): H04L29/06H04L9/32
CPCH04L9/3247H04L9/3268H04L63/0428H04L63/06H04L63/0823H04L63/0869H04L63/0884H04L63/1433H04L63/145
Inventor 王定健陈鲁符兴斌李锁在孟亚平陶亮吴伟袁野夏常钧
Owner 中软信息系统工程有限公司
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products