Netinfo Security ›› 2023, Vol. 23 ›› Issue (2): 11-18.doi: 10.3969/j.issn.1671-1122.2023.02.002

Previous Articles     Next Articles

Research on Integrity Measurement Scheme Based on Virtual Trusted Platform Module

QIN Zhongyuan(), GE Zhenwei, PAN Jingwei, CHEN Liquan   

  1. School of Cyber Science and Engineering, Southeast University, Nanjing 211189, China
  • Received:2022-07-05 Online:2023-02-10 Published:2023-02-28
  • Contact: QIN Zhongyuan E-mail:zyqin@seu.edu.cn

Abstract:

Aiming at the problem that the SHA-1 digest algorithm is no longer secure, which makes the hardware TPM untrustworthy, this paper proposed an integrity measurement scheme based on the virtual trusted platform module, added a new measurement framework called self-updating measurement, appended the summary value of the timestamp as additional content to the measurement component, and added random numbers to avoid clock attacks. At the same time, a self-updating log similar to the form of vTPM measurement list was designed to improve the measurement verification process. Finally, the functional verification was carried out in the experimental environment based on Xen. The experimental results show that this scheme can increase the attacker’s attack time cost squarely, and the security of the integrity measurement has been greatly improved.

Key words: trusted computing, TPM, integrity measurement, digest algorithms

CLC Number: