摘要
经过分析显示可信计算联盟(TCG)命令验证协议会受到一种基于Dolev-Yao模型的中间人攻击,对系统的可信性和安全性造成影响。针对该攻击,文章提出一种协议改进方法。在改进后的协议中,可信平台模块(TPM)和访问者能对会话状态进行有效的沟通,从而抵御中间人攻击。
This paper shows that the Trusted Computing Group(TCG) command validation protocols are exposed to a Dolev-Yao Man in The Middle(MiTM) attack, which will tamper with the security and the trustworthiness of the entire system. In order to avoid such attack, this paper proposes a countermeasure which makes an effective way through which the caller and TPM can well understand the session state of each other.
出处
《计算机工程》
CAS
CSCD
北大核心
2008年第22期159-161,共3页
Computer Engineering
基金
国家"863"计划基金资助项目(2007AA01Z483)
关键词
可信计算联盟
命令验证协议
中间人
Trusted Computing Group(TCG)
command validation protocols
Man in The Middle(MiTM)