系统仿真学报 ›› 2016, Vol. 28 ›› Issue (6): 1400-1405.

• 仿真系统与技术 • 上一篇    下一篇

USB安全连接方案设计与实现

赵松银, 郁滨   

  1. 信息工程大学,河南 郑州 450000
  • 收稿日期:2015-04-30 修回日期:2015-07-21 出版日期:2016-06-08 发布日期:2020-06-08
  • 作者简介:赵松银(1989-),男,河南新乡,硕士生,研究方向为USB、信息安全技术;郁滨(1964-),男,河南郑州,博士,教授,博导,研究方向为信息安全、无线网络安全技术、视觉密码等。
  • 基金资助:
    信息保障技术重点实验室开放基金(KJ-14-103); 河南省科技攻关项目(132102210003)

Design and Implementation of Secure USB Connection

Zhao Songyin, Yu Bin   

  1. Information Engineering University, Zhengzhou 450000, China
  • Received:2015-04-30 Revised:2015-07-21 Online:2016-06-08 Published:2020-06-08

摘要: 针对当前安全防护方案在应对USB硬件木马、BadUSB、总线窃听等新型攻击技术方面的不足,设计了一种与设备种类无关的USB安全连接方案。方案通过扩展标准设备请求,在USB连接建立过程中由集线器驱动程序与USB设备框架驱动进行双向认证与密钥协商,在数据传输过程中由USB总线驱动与USB设备框架驱动对I/O请求进行过滤加解密,实现了独立于设备种类的USB接入与传输安全。实验结果表明,方案可为信息系统构建安全封闭的USB连接,解决因USB接口引入的安全隐患

关键词: USB, 硬件木马, BadUSB, 窃听攻击, 集线器, 驱动

Abstract: Aiming at the deficiency of present secure solutions countering USB-based Hardware Trojan Horse, BadUSB, bus wiretapping and other new attack technologies, a secure connection scheme applying to any USB device was proposed. In scheme, mutual authentication and key exchange were implemented by extending the standard device request in the hub driver and USB device framework driver to prevent the creation of malicious USB connection. Meanwhile, all the data transferred of the created USB connection would be filter encrypted by USB bus driver and USB device framework driver to rebel the monitor of bus. The experiment results show that the proposed scheme can be used to build secure sealing USB connection for an information system, solving the secure threats introduced by USB interface.

Key words: USB, hardware trojan, BadUSB, wiretapping attack, hub, driver

中图分类号: