计算机工程与设计
計算機工程與設計
계산궤공정여설계
COMPUTER ENGINEERING AND DESIGN
2010年
4期
733-735,808
,共4页
李小将%梅栾芳%师俊芳%陈娟
李小將%梅欒芳%師俊芳%陳娟
리소장%매란방%사준방%진연
可信密码模块%嵌入式终端%微内核%可信根%可信链
可信密碼模塊%嵌入式終耑%微內覈%可信根%可信鏈
가신밀마모괴%감입식종단%미내핵%가신근%가신련
TCM%embedded terminal%mierokemel%trusted root%trusted chain
针对目前各种嵌入式终端的安全需求,借鉴普通安全PC中TPM的应用情况,结合操作系统微内核技术,提出一种嵌入式可信终端设计方案,该方案基于可信根TCM,实现了自启动代码、操作系统到上层应用程序的"自下而上"的可信链传递,适用于嵌入式终端的安全应用.最后,通过设计一个试验系统,重点阐述了可信启动的具体实现步骤,并分析了因此带来的性能变化.
針對目前各種嵌入式終耑的安全需求,藉鑒普通安全PC中TPM的應用情況,結閤操作繫統微內覈技術,提齣一種嵌入式可信終耑設計方案,該方案基于可信根TCM,實現瞭自啟動代碼、操作繫統到上層應用程序的"自下而上"的可信鏈傳遞,適用于嵌入式終耑的安全應用.最後,通過設計一箇試驗繫統,重點闡述瞭可信啟動的具體實現步驟,併分析瞭因此帶來的性能變化.
침대목전각충감입식종단적안전수구,차감보통안전PC중TPM적응용정황,결합조작계통미내핵기술,제출일충감입식가신종단설계방안,해방안기우가신근TCM,실현료자계동대마、조작계통도상층응용정서적"자하이상"적가신련전체,괄용우감입식종단적안전응용.최후,통과설계일개시험계통,중점천술료가신계동적구체실현보취,병분석료인차대래적성능변화.
According to the nowadays security requirement faced by embedded terminal,a design of embedded trusted terminal system is proposed to resolve the security problem referring to TPM application for the common security computer and microkemel technology.On basis of the TCM(trusted cryptography module)this scheme realizes trusted Bootloader,trusted operating system,trusted application program and constructs a integrated trusted chain from bottom to top,which is used in many security aress.Based on these,an experimental prototype is provided as an example to demonstrate the steps of implementing the trusted setup,and the result influence of performance is analyzed.