首页 | 官方网站   微博 | 高级检索  
     

基于TCM的安全Windows平台设计与实现
引用本文:冯 伟,秦 宇,冯登国,杨 波,张英骏. 基于TCM的安全Windows平台设计与实现[J]. 通信学报, 2015, 36(8): 91-103. DOI: 10.11959/j.issn.1000-436x.2015139
作者姓名:冯 伟  秦 宇  冯登国  杨 波  张英骏
作者单位:中国科学院软件研究所 可信计算与信息保障实验室,北京 100190
基金项目:国家自然科学基金资助项目(61202414, 91118006);国家重点基础研究发展计划(“973”计划)基金资助项目(2013CB338003)
摘    要:为了解决Windows系统的完整性度量与证明问题,提出了一种基于可信密码模块TCM (trusted cryptography module)的安全Windows平台方案。通过扩展Windows内核实现了2种安全模式:在度量模式下,所有加载的可执行程序都会被度量,度量值由TCM提供保护和对外认证;在管控模式下,度量值会进一步与管理员定制的白名单进行匹配,禁止所有不在白名单中的程序执行。实验分析表明,该方案可以增强Windows系统的安全性,抵抗一些软件攻击行为;同时,系统平均性能消耗在20~30 ms之间,不会影响Windows的正常运行。

关 键 词:可信计算;完整性度量;可信密码模块;Windows安全

Design and implementation of secure Windowsplatform based on TCM
Wei FENG,Yu QIN,Deng-guo FENG,Bo YANG,Ying-jun ZHANG. Design and implementation of secure Windowsplatform based on TCM[J]. Journal on Communications, 2015, 36(8): 91-103. DOI: 10.11959/j.issn.1000-436x.2015139
Authors:Wei FENG  Yu QIN  Deng-guo FENG  Bo YANG  Ying-jun ZHANG
Affiliation:Trusted Computing and Information Assurance Laboratory,Institute of Software,Chinese Academy of Science,Beijing 100190,China
Abstract:A secure Windows platform solution based on TCM was proposed to solve the integrity measurement and attestation problem of the Windows system. Two security modes were realized by extending the Windows kernel: in the measurement mode, all executable contents that were loaded onto the Windows system were measured, and the TCM provided the protection and outward attestation for these measurements; and in the control mode, the measurements were further compared with a whitelist customized by an administrator, and all the programs that were not included in the whitelist would be prohibited from running. Experiment analysis shows that proposed solution can enhance the security of Windows platform and resist some software attacks; and at the same time, the average performance overhead is about 20~30 ms, which will not influence the normal running of Windows.
Keywords:trusted computing   integrity measurement   trusted cryptography module   Windows security
点击此处可从《通信学报》浏览原始摘要信息
点击此处可从《通信学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号