节点文献

改进SeLinux构建可信计算平台

Improve SeLinux to Build Trusted Computing Platform

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 王畅刘美莲

【Author】 WANG Chang LIU Mei-lian (Information Engineering Institute,North China Institute of Water Conservancy and Hydroelectric Power (NCIWCHP), 450011, China)(Zhoukou Vocational Technology College, HeNan, Zhoukou, 466100, China)

【机构】 华北水利水电学院信息工程学院周口职业技术学院

【摘要】 安全操作系统是连接信任根和可信应用程序的桥梁。把TSPI(TCG Service Provider Interface)作为OS的特权系统调用来实现、把TSS(TPM Software Stack)软件栈作为一个独立的模块封装入OS内核,并在OS之上对TSPI进行面向服务的封装,将大大方便应用程序与TPM的交互。在OS内部添加可信服务访问控制(Trusted Service Access Ccontrol:TSAC)模块,确保具有平台属主权限的用户才能使用可信服务。信任链扩展到应用程序是一种复杂的可信服务,实现程序的完整性度量是信任链成功扩展的关键。采用分级的完整性测量方案能够高效地进行完整性测量,从而实现信任链的扩展。

【Abstract】 Trusted Root and Trusted Application are linked by the secure OS. TSPI ,the interface of TSS stack,is implemented as the privileged system call of OS.The rest of TSS is encapsulated as a independent module of OS kernel. Above OS, through service-oriented encapsulation, TSPI is improved as accessible trusted services.Calling these services application program interacts with TPM. TSAC Module is appended to OS kernel ensures that only the user who possesses platform owner rights can use the trusted services. Extending trusted chain to application program is a complicated process in which program integrity measurement is the crucial step. Adopting erarchical integrity testing can efficiently complete the task,then the extension of trusted chain is achieved.

【基金】 基金申请人:王畅;项目名称:Linux内核加载即时入侵防御模块实现安全增强;基金颁发部门:华北水利水电学院(HSQJ2008016)
  • 【文献出处】 微计算机信息 ,Microcomputer Information , 编辑部邮箱 ,2010年21期
  • 【分类号】TP316.81
  • 【被引频次】1
  • 【下载频次】111
节点文献中: 

本文链接的文献网络图示:

本文的引文网络