Skip navigation

DSpace JSPUI

DSpace preserves and enables easy and open access to all types of digital content including text, images, moving images, mpegs and data sets

Learn More
DSpace logo
English
中文
  • Browse
    • Communities
      & Collections
    • Publication Year
    • Author
    • Title
    • Subject
    • Advisor
  • Search TDR
  • Rights Q&A
    • My Page
    • Receive email
      updates
    • Edit Profile
  1. NTU Theses and Dissertations Repository
  2. 電機資訊學院
  3. 電機工程學系
Please use this identifier to cite or link to this item: http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/97966
Title: 可信執行環境保護的組合型隨機數產生器於無人機之應用
Combinatorial Random Number Generators Protected by Trusted Execution Environments for Drone Applications
Authors: 王思翰
Szu-Han Wang
Advisor: 吳沛遠
Pei-Yuan Wu
Co-Advisor: 賴怡吉
Alexander I-Chi Lai
Keyword: 隨機數產生器,熵源組合,可信任執行環境,無人機,
Random Number Generators,Entropy Source Combination,Trusted Execution Environment,Drones / Unmanned Aerial Vehicle (UAV),
Publication Year : 2025
Degree: 碩士
Abstract: 在現代資安架構中,隨機數產生器(Random Number Generator, RNG)的可靠性對於保護加密運算及提升系統對抗網路威脅的能力具有關鍵性影響。傳統設計普遍依賴單一熵源,當系統部分遭受攻擊時,尤其是在一般執行環境容易被外部攻擊的情境下,隨機數品質易受影響,進而削弱整體系統安全性。

本論文提出一套結合可信任執行環境(Trusted Execution Environment, TEE)與豐富執行環境(Rich Execution Environment, REE) 的組合型隨機數生成框架。此架構於 TEE 與 REE 中分別部署獨立的 RNG,並設計多種混合機制來融合兩個來源之隨機數。藉由跨域熵源混合與冗餘保護設計,即使其中一個熵源遭受破壞,最終隨機數輸出仍可保持高不可預測性,同時透過 TEE 的硬體隔離特性,進一步鞏固整體系統的安全韌性。

本研究使用 NIST SP800-22 隨機性測試套件進行評估,結果顯示所提出之組合型 RNG 在隨機性品質上能維持或優於單一熵源。為驗證其實務應用性,本架構亦整合至無人載具(Unmanned Aerial Vehicle, UAV)系統環境中,展示其於資源受限邊緣設備中提升隨機數安全性的效果。
Random number generators (RNGs) play a crucial role in cryptographic operations to establish cybersecurity defense. Traditional designs of RNGs, however, typically rely on a single entropy source, causing critical vulnerabilities to the overall system security.

To address the aforementioned challenge, this study proposes a combinatorial RNG scheme protected by a hybrid architecture combining a hardware-protected Trusted Execution Environment (TEE) and the conventional Rich Execution Environment (REE). In this framework, Independent RNGs are separately deployed in the TEE and REE domains, respectively, where their outputs are combined securely in TEE through selected techniques, including XOR operations, SHA-256 hashing, AES encryption, or chaining mechanisms. The hardware isolation enforced by TEE further protects the critical entropy sources as well as the combinatorial operation. By leveraging cross-domain entropy mixture and redundancy, the framework ensures that even if some entropy source is compromised, the final output remains adequately random. A benefit of such a framework is that some entropy sources can be placed outside TEE to save the critical security resources, without compromising the overall security level.

Extensive evaluations using the NIST SP800-22 randomness test suite verified that the proposed combinatorial RNG improves randomness quality compared to single-source RNGs. Moreover, the proposed approach was realized on a companion computer prototype for an unmanned aerial vehicle (UAV) to validate practical applicability, showcasing its potential to enhance randomness security in resource-constrained edge devices.
URI: http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/97966
DOI: 10.6342/NTU202501452
Fulltext Rights: 同意授權(全球公開)
metadata.dc.date.embargo-lift: 2025-07-24
Appears in Collections:電機工程學系

Files in This Item:
File SizeFormat 
ntu-113-2.pdf1.78 MBAdobe PDFView/Open
Show full item record


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

社群連結
聯絡資訊
10617臺北市大安區羅斯福路四段1號
No.1 Sec.4, Roosevelt Rd., Taipei, Taiwan, R.O.C. 106
Tel: (02)33662353
Email: ntuetds@ntu.edu.tw
意見箱
相關連結
館藏目錄
國內圖書館整合查詢 MetaCat
臺大學術典藏 NTU Scholars
臺大圖書館數位典藏館
本站聲明
© NTU Library All Rights Reserved