计算机工程与应用 ›› 2011, Vol. 47 ›› Issue (7): 110-113.

• 网络、通信、安全 • 上一篇    下一篇

基于属性的自证实模型及其安全协议

种惠芳,吴振强,王海燕   

  1. 陕西师范大学 计算机科学学院,西安 710062
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2011-03-01 发布日期:2011-03-01

Property-supported self-attestation model and its secure protocol

CHONG Huifang,WU Zhenqiang,WANG Haiyan   

  1. College of Computer Science,Shaanxi Normal University,Xi’an 710062,China
  • Received:1900-01-01 Revised:1900-01-01 Online:2011-03-01 Published:2011-03-01

摘要: 针对可信环境下被验证方需要向验证方发送其软硬件基本配置信息来证明其完整性而产生的攻击问题,给出一种基于虚拟机技术的属性自证实(PSA)模型及其安全协议,并对协议进行安全性分析。首先通过在被验证平台上建立一个可信虚拟机,然后由该虚拟机实现对被验证平台上其他组件的度量,并可靠地报告代表当前平台运行环境的安全属性给验证方。自证实方式可以提高通信的安全性,并且减少维护独立可信第三方时所需的开销;使用基于属性的远程证明方式,能够提高被验证方的安全性;安全协议引入了TPM的不可迁移密钥特性来防止假冒攻击的发生。

关键词: 远程证明, 可信计算, 属性证明

Abstract: For the reason of sending information about the hardware and software configuration of the attestator platform,who wants to attest its integrity to the challenger,may suffer attack of the challenger,a model based on virtualization technology named as Property-based Self-Attestation(PSA) is introduced.The protocol of this model is also given.A virtual machine acts as a verifier agent is set up on the attestator platform.The verifier agent gets the integrity attributes from the binary measurements,which come from the attestator,and gives them to the challenger to decide the attestation results.PSA model can reduce the costs using to maintain an independent trust agent,and improve the security.Using attributes to prove the integrity of attestator platform can improve the security of attestator.The security protocol uses the TPM’s non-migration key characteristic to resist the anonymous attack.

Key words: remote attestation, trusted computing, property attestation