首页 | 本学科首页   官方微博 | 高级检索  
     

可信终端动态运行环境的可信证据收集机制
引用本文:谭良,陈菊,周明天.可信终端动态运行环境的可信证据收集机制[J].电子学报,2013,41(1):77-85.
作者姓名:谭良  陈菊  周明天
作者单位:1. 四川师范大学计算机学院,四川成都610068;中国科学院计算技术研究所,北京100190
2. 四川师范大学计算机学院,四川成都,610068
3. 电子科技大学计算机科学与工程学院,四川成都,610054
基金项目:国家自然科学基金(No.60970113);四川省青年科技基金(No.2011JQ0038)
摘    要:可信计算的链式度量机制不容易扩展到终端所有应用程序,因而可信终端要始终保证其动态运行环境的可信仍然困难.为了提供可信终端动态运行环境客观、真实、全面的可信证据,提出了可信终端动态运行环境的可信证据收集机制.首先,在可信终端的应用层引入一个可信证据收集代理,并将该代理作为可信平台模块(trusted platform module,简称TPM)链式度量机制的重要一环,利用TPM提供的度量功能保证该代理可信;然后通过该代理收集可信终端的内存、CPU、网络端口、磁盘文件、策略配置数据和进程等的运行时状态信息,并利用TPM提供的可信存储功能,保存这些状态信息作为终端运行环境的可信证据,并保障可信证据本身的可信性.该可信证据收集机制具有良好的可扩展性,为支持面向不同应用的信任评估模型提供基础.在Windows平台中实现了一个可信证据收集代理的原型,并以一个开放的局域网为实验环境来分析可信证据收集代理所获取的终端动态运行环境可信证据以及可信证据收集代理在该应用实例中的性能开销.该应用实例验证了该方案的可行性.

关 键 词:可信计算  可信平台模块  动态运行环境  可信证据  可信终端
收稿时间:2011-06-21

Trustworthiness Evidence Collection Mechanism of Running Dynamic Environment of Trusted Terminal
TAN Liang , CHEN Ju , ZHOU Ming-tian.Trustworthiness Evidence Collection Mechanism of Running Dynamic Environment of Trusted Terminal[J].Acta Electronica Sinica,2013,41(1):77-85.
Authors:TAN Liang  CHEN Ju  ZHOU Ming-tian
Affiliation:1.College of Computer,Sichuan Normal University,Chengdu,Sichuan 610068,China;2.Institute of Computing Technology of Chinese Academy of Sciences,Beijing 100190,China;3.School of Computer Science & Engineering,University of Electronic Science & Technology of China,Chengdu,Sichuan 610054,China)
Abstract:Chain measurement mechanism of trusted computing don't easily extend to all applications in the terminal,so it is difficult for the terminal to always maintenance trust of the dynamic running environment of the terminal.To collect trustworthiness evidence in an objective,genuine and comprehensive way,this paper proposes a trustworthiness evidence collection mechanism of trusted terminal running dynamic environment.Firstly,a trusted evidence collection agent,whose creditability is assured by the measurement function of trusted platform module (TPM),is introduced by an application system in the terminal, the main function of which is collecting the information of the terminal dynamic running environment including memory,process,CPU,port of net,disk files,configure data and so on,and saving those evidences in Database or files by TPM.This mechanism has good scalability for various trustworthiness evaluation models.This paper also implements a prototype of the agent in Windows platform,and analyses the performance of agent in a local network distributed computing environment.This application demonstrates the feasibility of this mechanism.
Keywords:trusted computing  TPM (trusted platform module)  running environment  trustworthiness evidence  trusted terminal
本文献已被 CNKI 万方数据 等数据库收录!
点击此处可从《电子学报》浏览原始摘要信息
点击此处可从《电子学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号