检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:易平 庄毅[1] YI Ping;ZHUANG Yi(School of Computer Science and Technology,Nanjing University of Aeronautics and Astronautics, Nan.jing 211106, China)
机构地区:[1]南京航空航天大学计算机科学与技术学院,江苏南京211106
出 处:《计算机技术与发展》2018年第5期112-116,共5页Computer Technology and Development
基 金:国家自然科学基金(61572253);航空科学基金(2016ZC52030)
摘 要:针对嵌入式系统的安全问题,在充分考虑嵌入式系统的设计约束条件的基础上,借鉴可信计算的思想,提出一种基于虚拟技术的嵌入式可信平台构建方案。该平台基于分层内核架构,采用龙芯国产化处理平台,由增加SHA-1引擎的可信引导程序及可信内核模块构建核心度量根,其中可信内核是一个内嵌v TPM(virtualized trusted platform module)的精简操作系统,并依据该信任根设计了信任链传递模型。为缩短信任链的长度,采用联合度量方式对引导加载程序及可信内核进行完整性校验,用户内核是经过设计裁剪的嵌入式操作系统,运行在虚拟机上,实现了基于国产处理器的嵌入式平台可信计算环境的建立。实验结果表明,该方案在启动过程中完成从信任根到操作系统的完整性校验,且在不添加额外硬件的基础上,使系统的安全性得到了很大提高。Aiming at the security of embedded platform,based on the idea of trusted computing, fully considering the design constraints of embedded platform, we propose a method of constructing embedded trusted platform on account of virtual technology. It employs the do- mestic processor of LOONGSON based on the layered kernel architecture and establishes the core measure root by trusted bootloader that increases the SHA- 1 engine and trusted kernel modules. Trusted kernel contains viixual trusted platform module (vTPM) which can pro- vide cryptographic functions. In order to shorten the length of the trusted chain,boot loader and trusted kernel together can be measured as a whole to guarantee the integrity. The embedded operating system is designed and tailored to be user kernel, running on the virtual machine, and the establishment of embedded platform trusted computing environment based on domestic processor is realized. The experiments show that this method has built a trusted computing environment for embedded applications without additional hardware and improves the security of systems largely.
关 键 词:可信计算 龙芯处理器 虚拟技术 SHA-1 安全性
分 类 号:TP309.1[自动化与计算机技术—计算机系统结构]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.38