节点文献

TPM 2.0策略授权机制的安全缺陷及其改进方案

Security Risk and Improved Scheme for TPM 2.0 Policy Authorization

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 吴凯赵波米兰·黑娜亚提余发江

【Author】 Wu Kai;ZHAO Bo;Milan·Heinayati;YU Fajiang;School of Computer,Wuhan University;Key Laboratory of Aerospace Information Security and Trusted Computing of Ministry of Education,Wuhan University;Distance Learning College,Xinjiang Radio and TV University;

【机构】 武汉大学计算机学院空天信息安全与可信计算教育部重点实验室新疆广播电视大学远程教育学院

【摘要】 分析了可信平台模块TPM 2.0策略授权方式的安全性,开发了专门的灰盒测试系统对TPM 2.0的安全性进行了一系列测试,发现它存在两个潜在的安全隐患:信息泄露安全隐患和授权认证安全隐患.给出了利用该安全隐患暴力破解策略授权的实现方法并提出了一种基于共享密钥的授权会话加解密方案来对整个策略授权过程进行改进.实验结果表明,该改进方案可以很好的保证策略授权过程的安全性.

【Abstract】 The security of trusted platform module TPM 2.0policy authorization was analyzed.By using a specialized tools we designed,a series of gray-box testing was made,and two security risks information leakage and authentication risk were found.The attack method and an improved scheme based on shared key encryption were given.The experimental results show that the improved scheme can ensure the process of policy authorization security.

【基金】 国家重点基础研究发展计划(973)项目(2014CB340600);国家自然科学基金重点项目(61332019);国家自然科学基金(61173138,61272452,61103220)资助项目;湖北省重点新产品工艺研究开发项目(2012BAA03004);湖北省企业合作项目(YB2012120174,YB2013110084)
  • 【文献出处】 武汉大学学报(理学版) ,Journal of Wuhan University(Natural Science Edition) , 编辑部邮箱 ,2014年06期
  • 【分类号】TP393.08
  • 【被引频次】3
  • 【下载频次】196
节点文献中: 

本文链接的文献网络图示:

本文的引文网络