让-菲利普·奥马松与谢尔温·马杰里_加强银行级加密钱包的硬件安全模块.pdf

编号:175565 PDF 45页 2.42MB 下载积分:VIP专享
下载报告请您先登录!

让-菲利普·奥马松与谢尔温·马杰里_加强银行级加密钱包的硬件安全模块.pdf

1、Hardening HSMs for Hardening HSMs for BankingBanking-Grade Crypto WalletsGrade Crypto WalletsBlack Hat 2024Black Hat 2024JP Aumasson,Chervine MajeriJP Aumasson,Chervine MajeriWhoisWhoisJP Taurus co-founder&CSO First BHUS talk was in 2013 Chervine Taurus lead research engineer First BHUS talk is nowC

2、rypto asset custody&issuance for banks()regulated and running a marketplace for tokenized assets(t-)In Geneva,Zurich,London,Paris,Vancouver,DubaiOutlineOutline1.What is really an HSM?2.Security and crypto internals3.Attack surface and hardening4.Best practices&a note on cloud HSMsDisclaimer:This tal

3、k is based on our experience over 7 years with 3 HSM models,deployed in production in multiple environments.YMMV.Hardware security module(HSM)Hardware security module(HSM)“A dedicated crypto processor that is specifically designed for the protection of the crypto key lifecycle”(HSM vendor)Enterprise

4、/cloud HSMs usually 1RU or PCIE card form factorThe actual HSM is the module in the appliance/cardHSM purposeHSM purposeStore secretkeysfor crypto operations:Signature,decryption,symmetric encryption,MACHigh-assurance domain thanks to isolation&anti-tamperingProtect keys in case of servers/workstati

5、ons compromiseHSM use case examplesHSM use case examples Blockchain transaction signing and TEE Code signing(HSM mandatory for MS Win apps)Database encryption/decryption(usually via KEKs)PKI root of trust(for CAs,enterprise PKIs,etc.)https:/ interfacesHSM interfacesCrypto interface over PCIe or USB,

6、TCP/IP if network-attachedAdmin interface over serial port,SSH,HTTP/REST+TLS,GUISecurity mechanisms(1/4)Security mechanisms(1/4)Local isolation(slots aka partitions)Security mechanisms(2/4)Security mechanisms(2/4)Local isolation(slots aka partitions)RBAC,ABAC-ishmodel(with per-slot roles)Security me

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(让-菲利普·奥马松与谢尔温·马杰里_加强银行级加密钱包的硬件安全模块.pdf)为本站 (张5G) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠