季涛, 李永忠. 一种基于Xen的TPM访问控制改进方法[J]. 微电子学与计算机, 2012, 29(11): 152-156.
引用本文: 季涛, 李永忠. 一种基于Xen的TPM访问控制改进方法[J]. 微电子学与计算机, 2012, 29(11): 152-156.
JI Tao, LI Yong-zhong. An Improved Method of TPM Access Control Based on Xen[J]. Microelectronics & Computer, 2012, 29(11): 152-156.
Citation: JI Tao, LI Yong-zhong. An Improved Method of TPM Access Control Based on Xen[J]. Microelectronics & Computer, 2012, 29(11): 152-156.

一种基于Xen的TPM访问控制改进方法

An Improved Method of TPM Access Control Based on Xen

  • 摘要: 针对可信平台模块(TPM)访问受重放攻击和替换攻击威胁的问题,提出一种改进的TPM访问控制方法.首先建立TPM长期访问控制功能,通过创建额外授权数据以保证进程结束后继续授权会话,同时将TPM地址与Domain U的身份标识号相关联,以保护其地址免受替换攻击.其次,建立TPM所有权共享功能,允许多个DomainU使用相同的TPM地址并防止死锁,因共享地址不能被重写,可保护敏感数据免受攻击.最后基于Xen实现了该方法并评估了其性能.实验结果证明了该方法的可行性和有效性,TPM访问性能开销在可接受的范围内.

     

    Abstract: Aimed at solving the problem that TPM access was threatened by attacks such as replay attack and substitution attack, an improved method of TPM access control was proposed.First, TPM long term access control function was established.Extra authorization data was created to continue authorization session after finishing the process.Meanwhile, TPM address was related with an ID of Domain U to protect TPM address form substitution attack.Then, TPM shared ownership function was established, allowing plural Domain Us to use the same TPM address and preventing from the deadlock.Sensitive data was protected against attack because shared address was not rewritable.Finally, this method was implemented based on Xen and its performance was evaluated.Experiments results verified the feasibility and the effectiveness of this method and the overhead of TPM access was within the acceptable range.

     

/

返回文章
返回