详细信息
文献类型:期刊文献
中文题名:具有高表达能力的新型可信计算信任链的设计
英文题名:Highly-descriptive chain of trust in trusted computing
作者:龙宇[1];王辛[2];徐贤[3];洪璇[4]
机构:[1]上海交通大学计算机科学与工程系,上海200240;[2]国防科技大学计算机学院,长沙410073;[3]华东理工大学计算机科学与工程系,上海200237;[4]上海师范大学计算机系,上海200234
年份:2018
卷号:58
期号:4
起止页码:387
中文期刊名:清华大学学报(自然科学版)
外文期刊名:Journal of Tsinghua University(Science and Technology)
收录:CSTPCD;;EI(收录号:20183805830830);Scopus;北大核心:【北大核心2017】;CSCD:【CSCD2017_2018】;
基金:国家自然科学基金资助项目(61572318);上海市自然科学基金资助项目(14ZR1431000)
语种:中文
中文关键词:可信计算;基于身份的签名;信任链
外文关键词:trusted computing; identity based signature; chain of trust
摘要:基于可信计算芯片的可信启动指从信任根开始,通过建立信任链并沿信任链逐步移交系统控制权的过程。然而,现有信任链是简单的单链结构,并不能满足用户需要。该文首先参考基于身份的层次式签名机制,提出支持多软硬件系统的多信任链方案。该方案支持树状的多启动模块预期或信任路径。其次,参考基于身份的模糊签名机制,提出了支持多种潜在信任状态的信任链方案,该方案支持存在多潜在状态的单信任路径。最后,对上述2种方案进行结合。通过对支持多软硬件系统的方案进行扩充,实现末端节点的密钥拆分,并对回退机制、TPM(trusted platform module)芯片存储等部分进行修改,最终实现了兼有前述2种新信任链的功能的第3种方案:既支持多启动模块预期,又支持多种潜在的信任状态,从而满足用户在动态决定启动模块的同时动态决定信任状态的需求。
The trusted boot process in trusted computing verifies the next boot module from the root of trust to establish a chain of trust.The classic chain of trust is a simple single-branch tree,but this may not satisfy complete user demands. This paper presents a multi-module chain of trust model based on HIBS(hierarchical identity-based signature)and a multi-pattern chain of trust model based on FIBS(fuzzy identity based signature)that overcome the limitations of single module expectations in a traditional chain so that the user can dynamically choose the module.The two chains of trust models are then combined to improve the results.
参考文献:
正在载入数据...
