信息网络安全 ›› 2016, Vol. 16 ›› Issue (6): 22-27.doi: 10.3969/j.issn.1671-1122.2016.06.004

• • 上一篇    下一篇

基于TPCM的主动动态度量机制的研究与实现

田健生(), 詹静   

  1. 北京工业大学计算机学院,北京100124
  • 收稿日期:2016-04-18 出版日期:2016-06-20 发布日期:2020-05-13
  • 作者简介:

    作者简介: 田健生(1980—),男,河北,工程师,博士研究生,主要研究方向为信息安全;詹静(1982—),女,湖北,讲师,博士,主要研究方向为网络安全。

  • 基金资助:
    国家高技术研究发展计划(国家863计划)[2015AA016002];高等学校博士学科点专项科研基金[20131103120001];国防预研项目[10502020303]

Research and Implementation of Active Dynamic Measurement Based on TPCM

Jiansheng TIAN(), Jing ZHAN   

  1. College of Computer Science, Beijing University of Technology, Beijing 100124, China
  • Received:2016-04-18 Online:2016-06-20 Published:2020-05-13

摘要:

为了实现对系统的主动度量和控制,国内研究人员提出了基于可信平台控制模块(TPCM)的双系统并行体系结构, 但受限于硬件设计和制造能力,短期内难以完全实现。文章基于当前可信硬件基础,在保留主动度量能力的前提下对双系统体系结构进行了简化,基于可信平台控制模块设计并实现了系统运行中的主动动态度量机制,保障可信软件基(TSB)在完整运行周期中均能得到可信硬件的保护,有效解决了信息系统运行过程中可信软件基的自身安全保障问题。文章对主动动态度量机制的安全性进行了形式化证明, 分析了各环节中可能受到的攻击及应对方案,并对核心技术进行了工程实现和测试分析。

关键词: 主动度量, 动态度量, 可信平台控制模块, 可信软件基

Abstract:

In order to measurement and control the operating system, China has proposed a parallel dual system architecture based on trusted platform control module (TPCM). But limited to hardware design and manufacturing capabilities, it is difficult to fully achieve the short term. This paper simplified the dual system architecture based on current hardware foundation, while retain the ability of initiative measurement. Design and implement an Active dynamic measurement mechanism based on trusted platform control module. Ensure trusted software base (TSB) in the full life cycle can be protect by TPCM, Effectively solve TSB’s own safety and security in running system. In this paper, made the formalize proof to the active dynamic mechanism, analysis the various aspects may be attacked and gave solutions, implement and tested the core technology too.

Key words: active measurement, dynamic measurement, trusted platform control module (TPCM), trusted software base (TSB)

中图分类号: