期刊文献+

基于策略嵌入和可信计算的完整性主动动态度量架构 被引量:6

Policy embedded dynamic integrity active measurement architecture
下载PDF
导出
摘要 针对已有的一些完整性度量方法在度量主动性、灵活性和运行效率等方面的不足,提出了基于策略嵌入和可信计算的完整性主动动态度量架构(PEDIAMA)。将度量策略嵌入到度量目标内部,因此不需要专门的内存空间来集中维护所有的策略,节省了策略的查询和维护成本,提高了运行效率。由于策略方便存取,制订灵活,不仅可以实时接收外部的度量请求,也可以依据内嵌的策略主动进行度量,主动防御性更强。同时,通过TPM硬件来保护度量架构和度量过程的安全,并对度量策略和相关度量结果进行签名保护,提高了整个系统的安全性。经过测试,PEDIAMA能够即时检测出针对运行实体的攻击,并且度量开销较小。 In order to improve the current integrity measurement methods in activity,flexibility and efficiency,this paper presented a TPM-based architecture PEDIAMA(policy embedded dynamic integrity active measurement architecture).It embedded measurement policies into measurement targets,thus no extra memory was needed to hold and maintain the policies,and the cost in searching and maintaining was very low,so increased the efficiency of the whole system.As the policies were flexible in contents and easy to access,not only the external measurement requests could be fulfilled instantly,but also the embedded policies could be performed actively.For the architecture and the measurement process were protected by TPM,also protected the policies and some measurement results by digit signature,boosted the security of the whole system.Experimental results show that,PEDIAMA can instantly detect the attack aiming at running objects with lower overhead.
作者 邓锐 陈左宁
出处 《计算机应用研究》 CSCD 北大核心 2013年第1期261-264,共4页 Application Research of Computers
基金 国家重点基础研究发展计划资助项目(2007CB310900)
关键词 可信计算 完整性度量 策略嵌入 执行链接格式 动态度量 trust computing integrity measurement policy embedding ELF dynamic measurement
  • 相关文献

参考文献11

  • 1沈昌祥,张焕国,冯登国,曹珍富,黄继武.信息安全综述[J].中国科学(E辑),2007,37(2):129-150. 被引量:358
  • 2SAILER R, ZHANG Xiao-lan, JAEGER T,et al. Design and imple- mentation of a TCG-based integrity measurement architecture [ C ]/! Prec of the 13th Conference on USENIX Security Symposium. Berke- ley : USENIX Association ,2004:223-238. 被引量:1
  • 3JAEGER T, SAILER R, SHANKAR U. PRIMA: Policy-reduced in- tegrity measurement architecture[ C ]//Proc of the 11 th ACM Sympo- sium on Access Control Models and Technologies. New York: ACM Press ,2006 : 19-28. 被引量:1
  • 4SHI E, PERRIG A, Van DOORN L. BIND: a fine-grained attesta- tion service for secure distributed systems [ C ]//Proc of IEEE Sympo- sium on Security and Privacy. Washington DC : IEEE Computer Socie- ty,2005 : 154-168. 被引量:1
  • 5LOSCOCCO P A, WILSON P W, PENDERGRASS J A, et al. Linux kernel integrity measurement using contextual inspection [ C ]//Proc of ACM Workshop on Scalable Trusted Computing. New York: ACM Press ,2007:21-29. 被引量:1
  • 6THOBER M, PENDERGRASS J A, McDONELL C D: Improving co- herency of runtime integrity measurement [ C ]//Proc of the 3rd ACM Workshop on Scalable Trusted Computing. New York: ACM Press, 2008:51-60. 被引量:1
  • 7刘孜文,冯登国.基于可信计算的动态完整性度量架构[J].电子与信息学报,2010,32(4):875-879. 被引量:46
  • 8杨蓓,吴振强,符湘萍.基于可信计算的动态完整性度量模型[J].计算机工程,2012,38(2):78-81. 被引量:17
  • 9杨晓晖,周学海,田俊峰,李珍.一个新的软件行为动态可信评测模型[J].小型微型计算机系统,2010,31(11):2113-2120. 被引量:12
  • 10Tool Interface Standards (TIS) Committee. Executable and linking format(ELF) specification version 1.2 [ EB/OL ]. [ 2007- 01 - 26 3. http ://x86. ddj. cotn/ftp/manuals/tools/elf, pdf. 被引量:1

二级参考文献45

共引文献419

同被引文献56

引证文献6

二级引证文献7

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部