基于龙芯处理器的嵌入式可信解决方案  被引量:5

Design and Implementation of Embedded Trusted Platform Based on LOONGSON Processor

在线阅读下载全文

作  者:易平 庄毅[1] YI Ping;ZHUANG Yi(School of Computer Science and Technology,Nanjing University of Aeronautics and Astronautics, Nan.jing 211106, China)

机构地区:[1]南京航空航天大学计算机科学与技术学院,江苏南京211106

出  处:《计算机技术与发展》2018年第5期112-116,共5页Computer Technology and Development

基  金:国家自然科学基金(61572253);航空科学基金(2016ZC52030)

摘  要:针对嵌入式系统的安全问题,在充分考虑嵌入式系统的设计约束条件的基础上,借鉴可信计算的思想,提出一种基于虚拟技术的嵌入式可信平台构建方案。该平台基于分层内核架构,采用龙芯国产化处理平台,由增加SHA-1引擎的可信引导程序及可信内核模块构建核心度量根,其中可信内核是一个内嵌v TPM(virtualized trusted platform module)的精简操作系统,并依据该信任根设计了信任链传递模型。为缩短信任链的长度,采用联合度量方式对引导加载程序及可信内核进行完整性校验,用户内核是经过设计裁剪的嵌入式操作系统,运行在虚拟机上,实现了基于国产处理器的嵌入式平台可信计算环境的建立。实验结果表明,该方案在启动过程中完成从信任根到操作系统的完整性校验,且在不添加额外硬件的基础上,使系统的安全性得到了很大提高。Aiming at the security of embedded platform,based on the idea of trusted computing, fully considering the design constraints of embedded platform, we propose a method of constructing embedded trusted platform on account of virtual technology. It employs the do- mestic processor of LOONGSON based on the layered kernel architecture and establishes the core measure root by trusted bootloader that increases the SHA- 1 engine and trusted kernel modules. Trusted kernel contains viixual trusted platform module (vTPM) which can pro- vide cryptographic functions. In order to shorten the length of the trusted chain,boot loader and trusted kernel together can be measured as a whole to guarantee the integrity. The embedded operating system is designed and tailored to be user kernel, running on the virtual machine, and the establishment of embedded platform trusted computing environment based on domestic processor is realized. The experiments show that this method has built a trusted computing environment for embedded applications without additional hardware and improves the security of systems largely.

关 键 词:可信计算 龙芯处理器 虚拟技术 SHA-1 安全性 

分 类 号:TP309.1[自动化与计算机技术—计算机系统结构]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象