首页 | 本学科首页   官方微博 | 高级检索  
     

TPM用户密钥命令安全性形式化分析
引用本文:秦宇,赵世军,张倩颖. TPM用户密钥命令安全性形式化分析[J]. 中国通信, 2012, 9(10): 91-102
作者姓名:秦宇  赵世军  张倩颖
摘    要:

收稿时间:2012-11-22;

Formal Analysis of Trusted Platform Module Commands for Compromising User Key
Qin Yu,Zhao Shijun,Zhang Qianying. Formal Analysis of Trusted Platform Module Commands for Compromising User Key[J]. China Communications, 2012, 9(10): 91-102
Authors:Qin Yu  Zhao Shijun  Zhang Qianying
Affiliation:Institute of Software, Chinese Academy of Science, Beijing 100190, P. R. China
Abstract:The Trusted Platform Module (TPM) is a dedicated hardware chip designed to provide a higher level of security for computing platform. All TPM functionalities are implemented in TPM commands to achieve specific security goals. We attempt to analyze the security properties of these commands, especially the key management API. Our study utilizes applied pi calculus to formalize the commands and determine how their security properties affect TPM key management. The attacker is assumed to call TPM commands without bounds and without knowing the TPM root key, expecting to obtain or replace the user key. The analysis goal in our study is to guarantee the corresponding property of API execution and the integrity of API data. We analyze the security properties of TPM commands with a process reduction method, identify the key-handle hijack attack on a TPM newly created key, and propose reasonable solutions to solve the problem. Then, we conduct an experiment involving a key-handle attack, which successfully replaces a user key with an attacker's key using malicious TPM software. This paper discloses the weakness of the relationship between the key handle and the key object. After the TPM software stack is compromised, the attacker can launch a key-handle attack to obtain the user key and even break into the whole storage tree of user keys.
Keywords:trusted computing  TPM  TPM command  applied pi calculus  API analysis
点击此处可从《中国通信》浏览原始摘要信息
点击此处可从《中国通信》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号