信息网络安全 ›› 2023, Vol. 23 ›› Issue (2): 11-18.doi: 10.3969/j.issn.1671-1122.2023.02.002

• 技术研究 • 上一篇    下一篇

基于虚拟可信平台模块的完整性度量方案研究

秦中元(), 戈臻伟, 潘经纬, 陈立全   

  1. 东南大学网络空间安全学院,南京 211189
  • 收稿日期:2022-07-05 出版日期:2023-02-10 发布日期:2023-02-28
  • 通讯作者: 秦中元 E-mail:zyqin@seu.edu.cn
  • 作者简介:秦中元(1974—),男,河南,副教授,博士,主要研究方向为智能终端安全、人工智能安全、无线网络安全|戈臻伟(1998—),男,江苏,硕士研究生,主要研究方向为可信计算、二进制漏洞定位|潘经纬(1997—),男,安徽,硕士研究生,主要研究方向为可信计算、密码学|陈立全(1976—),男,广西,教授,博士,主要研究方向为移动信息安全、物联网系统与安全、云计算、大数据安全
  • 基金资助:
    国家重点研发计划(2020YFE0200600)

Research on Integrity Measurement Scheme Based on Virtual Trusted Platform Module

QIN Zhongyuan(), GE Zhenwei, PAN Jingwei, CHEN Liquan   

  1. School of Cyber Science and Engineering, Southeast University, Nanjing 211189, China
  • Received:2022-07-05 Online:2023-02-10 Published:2023-02-28
  • Contact: QIN Zhongyuan E-mail:zyqin@seu.edu.cn

摘要:

针对SHA-1摘要算法不安全导致硬件TPM不可信的问题,文章提出一种基于虚拟可信平台模块的完整性度量方案。该方案引入自更新度量框架,将时间戳的摘要值附于度量组件后,并加入随机数以规避时钟攻击。文章还设计了与vTPM度量列表形式相似的自更新日志,以完善度量验证。文章在基于Xen的实验环境下对方案进行功能性验证,实验结果表明,该方案可使攻击者的攻击时间成本呈平方级增加,完整性度量的安全性得到大幅度提高。

关键词: 可信计算, 可信平台模块, 完整性度量, 摘要算法

Abstract:

Aiming at the problem that the SHA-1 digest algorithm is no longer secure, which makes the hardware TPM untrustworthy, this paper proposed an integrity measurement scheme based on the virtual trusted platform module, added a new measurement framework called self-updating measurement, appended the summary value of the timestamp as additional content to the measurement component, and added random numbers to avoid clock attacks. At the same time, a self-updating log similar to the form of vTPM measurement list was designed to improve the measurement verification process. Finally, the functional verification was carried out in the experimental environment based on Xen. The experimental results show that this scheme can increase the attacker’s attack time cost squarely, and the security of the integrity measurement has been greatly improved.

Key words: trusted computing, TPM, integrity measurement, digest algorithms

中图分类号: