Original title:
Systém správy klíčů v jádře GNU/Linux
Translated title:
Key management in the GNU/Linux kernel
Authors:
Krejčí, Jáchym ; Komosný, Dan (referee) ; Sysel, Petr (advisor) Document type: Bachelor's theses
Year:
2026
Language:
cze Publisher:
Vysoké učení technické v Brně. Fakulta elektrotechniky a komunikačních technologií Abstract:
[cze][eng]
Tato bakalářská práce se zabývá systémem správy klíčů kernel keyrings v jádře operačního systému GNU/Linux. Cílem práce je popsat principy tohoto mechanismu, jeho využití pro bezpečné ukládání kryptografických klíčů a možnosti propojení s dalšími bezpečnostními a kryptografickými rozhraními Linuxu. Teoretická část popisuje bezpečnostní model Linuxu, základní typy kryptografických klíčů, architekturu kernel keyrings, nástroj keyctl a knihovnu keyutils. Součástí práce je také popis Trusted Platform Module (TPM), možností integrace s Kernel CryptoAPI a srovnání s vybranými mechanismy pro správu citlivých údajů v operačním systému Windows. Praktická část se zaměřuje na implementaci demonstrační aplikace v jazyce C. Aplikace představuje jednoduché rozhraní, které umožňuje uživateli zobrazovat dostupné keyringy, pracovat s uloženými klíči, provádět asymetrické kryptografické operace nad klíči uloženými v kernel keyrings, využívat TPM pro operace s privátní částí klíče a používat Kernel CryptoAPI pro symetrické šifrování a dešifrování souborů. Výsledkem práce je funkční nástroj demonstrující propojení kernel keyrings, TPM a Kernel CryptoAPI při správě a použití kryptografických klíčů v prostředí Linuxu.
This bachelor's thesis focuses on the kernel keyrings key management system in the GNU/Linux operating system kernel. The aim of the thesis is to describe the principles of this mechanism, its use for secure storage of cryptographic keys, and the possibilities of integration with other Linux security and cryptographic interfaces. The theoretical part describes the Linux security model, basic types of cryptographic keys, the architecture of kernel keyrings, the keyctl tool, and the keyutils library. The thesis also covers the Trusted Platform Module (TPM), integration with the Kernel CryptoAPI, and a comparison with selected mechanisms for managing sensitive data in the Windows operating system. The practical part focuses on the implementation of a demonstration application written in C. The application provides a simple interface that allows users to list available keyrings, work with stored keys, perform asymmetric cryptographic operations using keys stored in kernel keyrings, use TPM for operations involving the private part of a key, and use the Kernel CryptoAPI for symmetric file encryption and decryption. The result of the thesis is a functional tool demonstrating the integration of kernel keyrings, TPM, and the Kernel CryptoAPI for managing and using cryptographic keys in the Linux environment.
Keywords:
cryptographic keys; cryptography; decryption; encryption; GNU/Linux; Kernel CryptoAPI; kernel keyrings; keyctl; keyutils; TPM; dešifrování; GNU/Linux; Kernel CryptoAPI; kernel keyrings; keyctl; keyutils; kryptografické klíče; kryptografie; TPM; šifrování
Institution: Brno University of Technology
(web)
Document availability information: Fulltext is available in the Brno University of Technology Digital Library. Original record: http://hdl.handle.net/11012/258299