节点文献
改进SeLinux构建可信计算平台
Improve SeLinux to Build Trusted Computing Platform
【摘要】 安全操作系统是连接信任根和可信应用程序的桥梁。把TSPI(TCG Service Provider Interface)作为OS的特权系统调用来实现、把TSS(TPM Software Stack)软件栈作为一个独立的模块封装入OS内核,并在OS之上对TSPI进行面向服务的封装,将大大方便应用程序与TPM的交互。在OS内部添加可信服务访问控制(Trusted Service Access Ccontrol:TSAC)模块,确保具有平台属主权限的用户才能使用可信服务。信任链扩展到应用程序是一种复杂的可信服务,实现程序的完整性度量是信任链成功扩展的关键。采用分级的完整性测量方案能够高效地进行完整性测量,从而实现信任链的扩展。
【Abstract】 Trusted Root and Trusted Application are linked by the secure OS. TSPI ,the interface of TSS stack,is implemented as the privileged system call of OS.The rest of TSS is encapsulated as a independent module of OS kernel. Above OS, through service-oriented encapsulation, TSPI is improved as accessible trusted services.Calling these services application program interacts with TPM. TSAC Module is appended to OS kernel ensures that only the user who possesses platform owner rights can use the trusted services. Extending trusted chain to application program is a complicated process in which program integrity measurement is the crucial step. Adopting erarchical integrity testing can efficiently complete the task,then the extension of trusted chain is achieved.
【Key words】 trusted computing; Trused Service Access Control; extension of trusted chain; integrity measurement;
- 【文献出处】 微计算机信息 ,Microcomputer Information , 编辑部邮箱 ,2010年21期
- 【分类号】TP316.81
- 【被引频次】1
- 【下载频次】111