首页 | 官方网站   微博 | 高级检索  
     

一种基于软件源代码的远程证实方法
引用本文:阮安邦,,沈晴霓,,王立,,秦超,古亮,陈钟.一种基于软件源代码的远程证实方法[J].中国通信学报,2009,6(4):23-27.
作者姓名:阮安邦    沈晴霓    王立    秦超  古亮  陈钟
基金项目:This work is under support of National Natural Science Foundation of China under grant No. 60873238.
摘    要:The Binary-based attestation (BA) mechanism presented by the Trusted Computing Group can equip the application with the capability of genuinely identifying configurations of remote system. However, BA only supports the attestation for specific patterns of binary codes defined by a trusted party, mostly the software vendor, for a particular version of a software. In this paper, we present a Source-Code Oriented Attestation (SCOA) framework to enable custom built application to be attested to in the TCG attestation architecture. In SCOA, security attributes are bond with the source codes of an application instead of its binaries codes. With a proof chain generated by a Trusted Building System to record the building procedure, the challengers can determine whether the binary interacted with is genuinely built from a particular set of source codes. Moreover, with the security attribute certificates assigned to the source codes, they can determine the trustworthiness of the binary. In this paper, we present a TBS implementation with virtualization.

关 键 词:计算机网络  通信  BA  TCG
收稿时间:2011-07-15;

Towards a Source-Code Oriented Attestation
Ruan Anbang,,Shen Qingni,,Wang Li,,Qin Chao,Gu Liang,Chen Zhong,.Towards a Source-Code Oriented Attestation[J].China communications magazine,2009,6(4):23-27.
Authors:Ruan Anbang      Shen Qingni      Wang Li      Qin Chao  Gu Liang    Chen Zhong    
Affiliation:1School of Software and Microelectronics, Peking University, Beijing 102600, China
2Network and Information Security Laboratory, Institute of Software, School of Electronics Engineering and Computer Science, Peking University, Beijing 100871, China
3Key Laboratory of High Confidence Software Technologies of the Ministry of Education, Peking University, Beijing 100871, China
4First Research Institute of Ministry of Public Security of China, Beijing 100048, China
Abstract:In this paper, we present a Source-Code Oriented Attestation (SCOA) framework to enable custom build application to be attested to in the TCG attestation architecture. In SCOA, security attributes are bond the source codes of an application instead of its binaries codes. With a proof chain generated by a Trusted Building System to record the building procedure, the challengers can determine whether the binary its is interacting with is genuinely built from a particular set of source codes. Moreover, with the security attribute certificates assigned to the source codes, they can determine the trustworthiness of the binary. In this paper, we present a TBS implementation with virtualization.
Keywords:remote attestation  trusted building system  virtualization  source-code
本文献已被 维普 等数据库收录!
点击此处可从《中国通信学报》浏览原始摘要信息
点击此处可从《中国通信学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号