首页 | 官方网站   微博 | 高级检索  
     

TRSF:一种移动存储设备主动防护框架
引用本文:马俊,王志英,任江春,刘聪,伍江江,程勇,梅松竹.TRSF:一种移动存储设备主动防护框架[J].电子学报,2012,40(2):376-383.
作者姓名:马俊  王志英  任江春  刘聪  伍江江  程勇  梅松竹
作者单位:国防科技大学计算机学院,湖南长沙,410073
基金项目:国家自然科学基金青年基金,核高基重大专项
摘    要: 移动存储设备属于被动设备,其安全防护往往依赖于终端系统的安全机制,在提供安全性的同时会降低系统可用性.本文提出了一种基于可信虚拟域的移动存储设备结构框架TRSF(Trusted Removable Storage Framework)实现存储设备的主动防护.TRSF将智能卡芯片和动态隔离机制绑定到存储设备中,并由片上操作系统构建从底层可信平台模块到隔离运行环境的可信数据通道,从而为移动存储设备在非可信终端系统中被非可信进程访问和使用提供一个可信虚拟环境.最后基于TRSF实现了一款主动安全U盘UTrustDisk.与没有增加主动防护机制相比,增加该机制导致平均读写性能开销分别增加了7.5%和11.5%.

关 键 词:可信虚拟域  主动防护  可信存储  信任链  隔离  片上操作系统
收稿时间:2010-12-21

TRSF: Implementing Active Removable Storage Protection via Trusted Virtual Domains
MA Jun , WANG Zhi-ying , REN Jiang-chun , LIU Cong , WU Jiang-iiang , CHENG Yong , MEI Song-zhu.TRSF: Implementing Active Removable Storage Protection via Trusted Virtual Domains[J].Acta Electronica Sinica,2012,40(2):376-383.
Authors:MA Jun  WANG Zhi-ying  REN Jiang-chun  LIU Cong  WU Jiang-iiang  CHENG Yong  MEI Song-zhu
Affiliation:(School of Computer,National University of Defense Technology,Changsha,Hunan 410073,China)
Abstract:As removable storage medias are passive devices,their security policies depend on mechanisms in connected terminal systems,which will reduce the availability while providing security.This paper presents TRSF,a framework of removable storage based on trust virtual domain to implement active protection.TRSF solidifies a smart card and an isolation mechanism into the storage device and builds trust data channels from the device to the isolated usage environment in terminal system.So TRSF is able to provide trust virtual environment for data access and usage of removable storage even in untrust terminal systems by untrust processes.We implement an intelligent USB disk based on TRSF called UTrustDisk to evaluate the framework.The average overhead on read and write caused by trust chain mechanism is 7.5% and 11.5%.
Keywords:trusted virtual domains(TVDs)  active protection  trusted storage  trust chain  isolation  chip operation system(COS)
本文献已被 CNKI 万方数据 等数据库收录!
点击此处可从《电子学报》浏览原始摘要信息
点击此处可从《电子学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号