首页 | 本学科首页   官方微博 | 高级检索  
     

虚拟可信平台模块动态信任扩展方法
引用本文:余发江,陈列,张焕国.虚拟可信平台模块动态信任扩展方法[J].软件学报,2017,28(10):2782-2796.
作者姓名:余发江  陈列  张焕国
作者单位:武汉大学 计算机学院, 湖北 武汉 430072;软件工程国家重点实验室(武汉大学), 湖北 武汉 430072,武汉大学 计算机学院, 湖北 武汉 430072,武汉大学 计算机学院, 湖北 武汉 430072;软件工程国家重点实验室(武汉大学), 湖北 武汉 430072
基金项目:国家重点基础研究发展计划(973)(2014CB340600);国家自然科学基金(61772384)
摘    要:将可信计算技术应用到虚拟计算系统中,可以在云计算、网络功能虚拟化(network function virtualization,简称NFV)等场景下,提供基于硬件的可信保护功能.软件实现的虚拟可信平台模块(virtual trused platform module,简称vTPM)基于一个物理TPM(physical TPM,简称pTPM),可让每个虚拟机拥有自己专属的TPM,但需要将对pTPM的信任扩展到vTPM上.现有方法主要采用证书链来进行扩展,但在虚拟机及其vTPM被迁移后,需要重新申请vTPM的身份密钥证书,可能会存在大量的短命证书,成本较高,且不能及时撤销旧pTPM对vTPM的信任扩展,也不能提供前向安全保证.提出了一种vTPM动态信任扩展(dynamic trust extension,简称DTE)方法,以满足虚拟机频繁迁移的需求.DTE将vTPM看作是pTPM的一个代理,vTPM每次进行远程证明时,需从一个认证服务器(authenticaiton server,简称AS)处获得一个有效的时间令牌.DTE在vTPM和pTPM之间建立了紧密的安全绑定关系,同时又能明显区分两种不同安全强度的TPM.在DTE里,vTPM被迁移后,无需重新获取身份秘钥证书,旧pTPM可及时撤销对vTPM的信任扩展,而且DTE可提供前向安全性.从原型系统及其性能测试与分析来看,DTE是可行的.

关 键 词:可信计算  可信平台模块(TPM)  虚拟可信平台模块(vTPM)  信任扩展
收稿时间:2016/7/25 0:00:00
修稿时间:2016/9/29 0:00:00

Virtual Trusted Platform Module Dynamic Trust Extension
YU Fa-Jiang,CHEN Lie and ZHANG Huan-Guo.Virtual Trusted Platform Module Dynamic Trust Extension[J].Journal of Software,2017,28(10):2782-2796.
Authors:YU Fa-Jiang  CHEN Lie and ZHANG Huan-Guo
Affiliation:School of Computer, Wuhan University, Wuhan 430072, China;State Key Laboratory of Software Engineering (Wuhan University), Wuhan 430072, China,School of Computer, Wuhan University, Wuhan 430072, China and School of Computer, Wuhan University, Wuhan 430072, China;State Key Laboratory of Software Engineering (Wuhan University), Wuhan 430072, China
Abstract:The integration of trusted computing into virtual computing system can enable the hardware-based protection of trustworthiness in application areas such as cloud computing and network function virtualization (NFV).In a physical trusted platform module (pTPM) based virtual trusted platform module (vTPM), each virtual machine (VM) can be viewed as having its own private TPM.However, it is necessary to extend the trustworthiness of pTPM to vTPM so that a challenger can believe the vTPM is the root of trust of the VM.The existing techniques mainly use a certificate chain to build a trust link from pTPM to vTPM.But if these techniques were deployed in the scenario with frequent vTPM migrations, there would be very high cost of reacquiring new certificates for the migrated vTPM, moreover, pTPM couldn''t revoke its trust extension in real time, and they couldn''t provide forward security.This paper presents an approach of vTPM dynamic trust extension (DTE) to satisfy the requirements of frequent migrations.With DTE, vTPM is a delegation of the capability of signing attestation data from the underlying pTPM, with one valid time token issued by an authentication server (AS).DTE maintains a strong association between vTPM and its underlying pTPM, and has clear distinguishability between vTPM and pTPM because of the different security strength of the two types of TPM.In DTE, there is no need for vTPM to re-acquire identity key (IK) certificate(s) after migration, and pTPM can have a trust revocation in real time.Furthermore, DTE can provide forward security.Performance measurements and analysis of its prototype demonstrate that DTE is feasible.
Keywords:trusted computing  trusted platform module (TPM)  virtual trusted platform module (vTPM)  trust extension
点击此处可从《软件学报》浏览原始摘要信息
点击此处可从《软件学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号