当前位置:首页 > 报告详情

6520 - An Update on OCP L.O.C.K..pdf

上传人: 芦苇 编号:651484 2025-05-01 21页 816.58KB

1、An Update on OCP L.O.C.K.LayeredOpen-sourceCryptographicKey-managementJeff Andersen,GoogleEric Eilertson,MicrosoftAn Update on OCP L.O.C.K.Room for improvement in storage securityAuditing of cryptographic purgeData access authorization modelDrive encryption implementation qualityA project to deliver

2、 an open implementation at CHIPS Alliance,coupled with new storage APIs defined at TCG(Trusted Computing Group)Scoped specifically to storage devicesProvides key management services to the drive and host,utilizing services from CaliptraOCP L.O.C.K.L.O.C.K.LayeredOpen-sourceCryptographicKey-managemen

3、tStandard interface for media key programmingStandard interface for media key programmingKMB:Key Management BlockAES crypto engineStorage controller firmwareAES engine interface(new)Lets KMB securely communicate media keysto the crypto engine,without exposing to firmwareAES crypto engineMetadata_1Au

4、x_1MEK_1Metadata_2Aux_2MEK_2Metadata_nAux_nMEK_nStandard interface for media key programmingKey cacheKMBSet metadata,aux,MEKDoneRemove metadataDoneMEK=media encryption keyData I/OAES crypto engineMetadata_1Aux_1MEK_1Metadata_2Aux_2MEK_2Metadata_nAux_nMEK_nStandard interface for media key programming

5、Key cacheRegisterAddressByte sizeControlSFR_BASE+0h4hMetadata(i.e.NSID+LBA range)SFR_BASE+10h14hAux(i.e.operational mode)SFR_BASE+30h20hMEKSFR_BASE+50h40hMEK=media encryption keyAccess control in TCG OpalAccess control in TCG OpalRecall:TCG Opal supports default or single-user modeUser PINAdmin PINO

6、RDefault caseUser PINSingle-User ModeUser 1User 2User 1 PINUser 2 PINAccess control in TCG OpalUser 1User 2User 1 PINUser 2 PINKey Management ServiceWe would like media keys to be gated by an access key held by the platform.Customer VMPlatform firmwareHost OSTPMAccess control in TCG OpalUser 1User 2

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要介绍了OCP L.O.C.K.(Layered Open-source Cryptographic Key-management)项目的更新。该项目旨在提供一种开放的、分层的、基于开源的加密密钥管理方案,专注于存储设备的密钥管理服务。主要更新包括:1)在CHIPS Alliance上提供开放的实现,并与TCG(可信计算组)定义的新存储API相结合;2)引入了“时代密钥”(Epoch keys),支持有限次数的单次使用熔丝擦除,以实现可验证的加密擦除;3)提出了一个新的数据访问授权模型,以及存储安全中的审计改进;4)强调了加密实现质量的重要性,并呼吁社区参与OCP L.O.C.K.的规范制定和实施过程。
"OCP L.O.C.K.如何提高存储安全?" "如何通过TCG Opal实现访问控制?" "L.O.C.K.项目如何改进加密擦除技术?"
客服
商务合作
小程序
服务号
折叠