首页> 外文会议>Proceedings of the 9th international conference for young computer scientists (ICYCS 2008) >A Secure and Reliable Platform Conguration Change Reporting Mechanism for Trusted Computing Enhanced Secure Channels
【24h】

A Secure and Reliable Platform Conguration Change Reporting Mechanism for Trusted Computing Enhanced Secure Channels

机译:用于可信计算的安全可靠的平台配置更改报告机制增强了安全通道

获取原文

摘要

The security of well established secure channel technologies like transport layer security (TLS) or IP security (IPSec) can be signi.cantly improved by emerging concepts like Trusted Computing. The use of trusted platform modules (TPMs) offers new methods for improving the security of these well established technologies. How secure channel technologies can be adapted to use trusted computing concepts is subject to current research. A major part of this research addresses the integration of the TCG's speci.ed remote attestation. Remote attestation enables a platform to provide a trustworthy proof of its current con.guration (i.e. software that has been loaded on the platform). Hence, based on this proof, a remote platform can decide whether to open a channel to another platform or not. In current approaches, the proof of the platform con.guration is processed before a secure channel is established, which is not opened if the reported con.guration is not accepted by the hosts. However, one important problem has not been solved yet. Currently, no satisfying solution how the change of a platform's con.guration can be securely and reliably reported to the remote platform whilst a channel is open, exists. A reliable method to provide a proof for a con.guration change can be implemented with only minor modi.cations of the TPM speci.cation and the TLS protocol. Experimental results show that it is possible to implement this proof mechanism with only a few additional TPM commands.
机译:诸如可信计算之类的新兴概念可以显着提高完善的安全通道技术(如传输层安全性(TLS)或IP安全性(IPSec))的安全性。可信平台模块(TPM)的使用为提高这些完善技术的安全性提供了新方法。当前如何研究如何使安全通道技术适应使用可信计算概念。这项研究的主要内容是解决TCG指定的远程证明的集成。远程证明使平台能够提供其当前配置的可信赖的证明(即已加载到平台上的软件)。因此,基于此证明,远程平台可以决定是否打开到另一个平台的通道。在当前的方法中,在安全通道建立之前处理平台配置的证明,如果所报告的配置未被主机接受,则不会打开该平台。但是,尚未解决一个重要问题。当前,尚不存在令人满意的解决方案,该技术如何在通道打开的情况下安全可靠地向远程平台报告平台配置的更改。只需对TPM规范和TLS协议进行较小的修改就可以实现一种可靠的方法来证明配置更改。实验结果表明,仅用几个附加的TPM命令就可以实现这种证明机制。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号