首页|期刊导航|集成电路与嵌入式系统|基于安全固态硬盘的TPCM关键技术研究及实现

基于安全固态硬盘的TPCM关键技术研究及实现OA

Research and implementation of key technologies of TPCM based on secure SSD

中文摘要英文摘要

面对新时期网络空间安全形势,我国适时提出了基于可信计算3.0的主动免疫防护体系.结合可信平台控制模块(TPCM)国家标准规范,提出一种基于安全固态硬盘的 TPCM 方案及其实现方法.通过安全控制芯片内置的SM2、SM3、SM4、随机数模块、OTP控制器模块等实现了安全控制芯片的上电自检、安全启动、数据加解密及密钥管理功能.然后基于安全固态硬盘设计了认证软件,实现了对计算机主板、BIOS、外设及IP地址等物理环境的可信启动度量及响应,与已有的TPCM 板卡相比,提出的方案将可信度量提前到系统盘的安全可信启动,具有安全性高、兼容性好、扩展性强、部署方便、成本低等优点.

Facing the new era's cybersecurity situation,China has timely proposed an active immune protection system based on trusted computing 3.0.Combined with the national standard specifications of the Trusted Platform Control Module(TPCM)in China,a TPCM module solution based on a secure SSD and its implementation method are proposed.Through the built-in SM2,SM3,SM4,random number generator module,and OTP controller module of the security control chip,the power-on self-test,secure boot,data encryption and decryption,and key management functions of the security control chip are realized.Based on the secure SSD,an authentication soft-ware is designed to achieve the trusted boot measurement and response of the physical environment such as the computer motherboard,BIOS,peripherals,and IP address.Compared with the existing TPCM cards,the proposed solution brings the credibility measurement forward to the secure and trusted boot of the SSD,which has the advantages of high security,good compatibility,strong scalability,convenient deployment,and low cost.

刘海亮;曾伟;朱争琼;杨万云

芯盛智能科技(湖南)有限公司,长沙 410119||成都芯盛集成电路有限公司,成都 610213芯盛智能科技(湖南)有限公司,长沙 410119||成都芯盛集成电路有限公司,成都 610213芯盛智能科技(湖南)有限公司,长沙 410119||成都芯盛集成电路有限公司,成都 610213芯盛智能科技(湖南)有限公司,长沙 410119||成都芯盛集成电路有限公司,成都 610213

信息技术与安全科学

可信计算可信平台控制模块固态硬盘安全芯片主动免疫防护

trusted computingtrusted platform control moduleSSDsecurity control chipactive immune protection

《集成电路与嵌入式系统》 2026 (7)

89-98,10

信息网络安全公安部重点实验室基金资助项目(C22609)四川省科技计划资助项目(2025JDRC0008)

10.20193/j.ices2097-4191.2026.0009

评论