期刊文献+

Ng-vTPM:新一代TPM虚拟化框架设计 被引量:9

Ng-v TPM: A Next Generation Virtualized TPM Architecture
原文传递
导出
摘要 虚拟可信平台模块v TPM(virtual trusted platform module)是云环境中提供可信功能的重要部件,针对已有v TPM在安全存储属性、可信身份属性、信任传递属性以及迁移时这些属性的保持在设计上的不足,本文提出一个Ng-v TPM框架.该框架结合TPM2.0的新特性,由物理TPM产生v TPM密钥提供安全存储属性,基于物理TPM背书平台种子与虚拟背书密钥的映射关系,提供虚拟机可信身份,将信任链由物理平台扩展到虚拟机平台,并提出使用基于平台配置寄存器策略的封装存储方法解决v TPM迁移后数据的可用性.最后以Xen-4.3.0架构为基础实现此框架.实验分析表明,该框架能够有效保证v TPM设计的安全需求. As a vital important security component in cloud,v TPM( virtual trusted platform module) should provide the abilities of seal storage,trust identity and chain of trust,as well as trust migration. Unfortunately,those requirements are far from ongoing research works. In this paper,a Ng-v TPM framework is proposed. This framework has three features,the first one is a novel v TPM key hierarchies to protect sensitive data,the second one is the extension of chain of trust from physical host hardware to virtualized guest environment based on EPS( Endorsement Platform Seed),the third one is a novel PCR( platform configuration register) policy based on sealing to solve brittleness problem for migratable v TPM. At last,we also implement this framework on Xen and TPM 2. 0 platform. According to the experiments and data analysis,our work can satisfy the above requirements correctly and efficiently.
出处 《武汉大学学报(理学版)》 CAS CSCD 北大核心 2015年第2期103-111,共9页 Journal of Wuhan University:Natural Science Edition
基金 国家重点基础研究发展计划(973)项目(2014CB340600) 国家自然科学基金(61272452 61003268 61173138 91118003 61303024)资助项目
关键词 可信计算 虚拟可信平台模块 TPM 2.0 增强授权 trusted computing virtual trusted platform module TPM 2.0 enhancement authorization
  • 相关文献

参考文献17

  • 1Trusted Computing Group. Trusted Platform Module Specification Family 2.0 Level 00 Revision 00.99[EB/ OL]. [2014-03-10]. http://zvzvzv, trustedcomputiT g group, org/resources/tpm main specification. 被引量:1
  • 2lntel Corp. lntel Trusted Execution Technology[EB/ OL].. E2014-03 101. http://www, intel, com/tect nolo gy/security/. 被引量:1
  • 3Zhang F, Chen J, Chen H, etal. Cloudvisor; Retro fitting protection of virtual machines in multi tenant cloud with nested virtualization[C]//Proceedings of the Tzventy-Third ACM Press Symposium on Operat ing Systems Principles. New York: ACM, 2011: 203-216. 被引量:1
  • 4Berger S, Caceres R,Goldman K, etal. VTPM: Vir- tualizing the trusted platform module[C]//Proceed- ings of the 15th USENIX Security Symzposiun .Or lando: VSENIZ, 2006: 305 320. 被引量:1
  • 5Sadeghi A, Stuble C, Winandy M. Property-based TPM virtualization[C]//Proceedings of the llth In- ternational Conference on Information Security, ISC'08, Berlin : Springer-Verlag , 2008:1-16. 被引量:1
  • 6Yap J Y, Tomlinson A. Para-virtualizing the trusted platform module: An enterprise framework based on version 2. 0 specifieation[ C]//5th International Con- ference, INTRUST 2013. Berlin: Springer-Verlag, 2013:1-16. 被引量:1
  • 7England P, Loeser J: Para-virtualized TPM sharing [C]//Proceedings of the 1st International Conference on Trusted Computing and Trust in Information Technologies: Trusted Computing-Challenges and Applications, TRUST 08. Berlin: Springer-Verlag, 2008:119-132. 被引量:1
  • 8Jayaram M R, Marforio C, Capkun S. An architecture for concurrent execution of secure environments in elouds[C]//Proceedings of the 2013 ACM Workshop on Cloud Computing Security Workshop. New York: ACM Press, 2013: 11-22. 被引量:1
  • 9Stumpf F, Eekert C. Enhancing Trusted Platform Modules with Hardware-Based Virtualization Tech- niques [ C ]//Proceedings of the 2nd International Conference on Emerging Security Information, Sys- tems and Technologies(SECURWARE'08). Washing- ton DC:IEEE, 2008: 1-9. 被引量:1
  • 10Santos N, Rodrigues R, Gummadi K P, etal. Policy- sealed data: A new abstraction for building trusted cloud services [C]//Security 12 Proceedings of the 21st USENIX Conference on Security Symposium. CA USA.- USENIX Association, 2012 : 10. 被引量:1

同被引文献59

引证文献9

二级引证文献42

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部