计算机工程与应用 ›› 2008, Vol. 44 ›› Issue (16): 126-128.

• 网络、通信、安全 • 上一篇    下一篇

一个基于可信计算技术的可信下载协议

刘民岷1,孙世新2,刘 璟3   

  1. 1.电子科技大学 机械电子工程学院,成都 610054
    2.电子科技大学 计算机学院,成都 610054
    3.中山大学 信息学院 计算机系,广州 510275
  • 收稿日期:2007-09-25 修回日期:2007-12-12 出版日期:2008-06-01 发布日期:2008-06-01
  • 通讯作者: 刘民岷

Trusted download protocol based on trusted computing technology

LIU Min-min1,SUN Shi-xin2,LIU Jing3   

  1. 1.College of Mechanical & Electronic Engineering,University of Electronic Science and Technology of China,Chengdu 610054,China
    2.College of Computer S&E,University of Electronic Science and Technology of China,Chengdu 610054,China
    3.Department of Computer Science,School of Information Science and Technology,Sun Yat-Sen University,Guangzhou 510275,China
  • Received:2007-09-25 Revised:2007-12-12 Online:2008-06-01 Published:2008-06-01
  • Contact: LIU Min-min

摘要: 私有代理程序在开放网络中因为业务需要而进行迁移是一个常见的活动,如何保证接收方主机平台不受恶意程序攻击,同时又要确认接收方平台的可信度是一个具有普遍意义的问题。利用可信计算技术,设计了一个可信下载协议,有效地解决了上述问题,并利用AVISPA工具包对协议进行了验证,验证结果表明该协议实现了双向平台完整性鉴别、双向实体鉴别以及私有代理程序在迁移过程中的机密性和完整性。

关键词: 可信计算, 可信下载, 私有代理程序

Abstract: It is very common that proprietary agent has to migrate in the environment of open network to fulfill the business logic efficiently.In this case,how to protect the recipient’s platform from malicious code,and at the same time how to attest to the trustworthiness of the recipient’s platform by the recipient are both typical problems.Utilizing trusted computing technology,we design a trusted download protocol and solve the aforementioned problems efficiently.We also use AVISPA toolset to verify this protocol and the results of verification demonstrate that this protocol does realize mutual platform integrity authentication,mutual entity authentication and confidentiality and integrity of proprietary agent during transit.

Key words: trusted computing, trusted download, proprietary agent