摘要
现有远程证明实现方法从度量静态二进制代码、平台配置文件到安全策略监控来衡量目标平台的可信性,但这些方法灵活性和可行性不强,对可信平台客户端配置要求较高且尚未成熟。文中利用IMA机制改进了传统TCG远程证明方案,增加了度量的灵活性,减小了可信平台客户端压力;同时加入了密钥托管机制,解决了可信计算密钥托管和恢复问题。
Existing approaches for realization of the remote attestation measure the trustworthiness of a target platform from its binaries, configurations, properties or security policies. However, the flexibility and feasibility of these methods is still not good and not mature. Moreover, it requires very high capability of trusted platform client. By using IMA, the traditional TCG remote attestation is improved. The new architecture has increased the flexibility of the measurement, reduced the pressure of the trusted platform client; and by adding the key escrow mechanism, solved the key escrow and restoration problem in TCG.
出处
《通信技术》
2009年第4期102-104,共3页
Communications Technology
基金
国家自然科学基金资助项目(编号:60573003)
关键词
远程证明
密钥托管
完整性度量方案
remote attestation: key escrow: integrity measurement architecture