摘要
为进一步提高BIOS的安全性,提出一种利用可信平台模块(TPM)在可扩展固件接口(EFI)中建立可信链的方案。该方案通过对EFI启动过程的分析,建立了一条从EFI的第一个阶段开始,一直到操作系统的可信链。从而较大地缩小了信任根的范围,使得BIOS的安全性得到很大程度的提高。随着EFI的普及,这将在实现安全计算机系统上具有较好的应用前景。
To further enhance the safety of BIOS, this paper presented a new trust transition model with Trusted Platform Module (TPM) in Extensible Firmware Interface (EFI). This model established a trust chain from the first stage of EFI to the operating system by analyzing the process of EFI startup. Thus the model narrowed the scope of the root of trust and substantially improved the safety of the BIOS. With the popularity of EFI, this model has a good prospect in achieving security on computer system.
出处
《计算机应用》
CSCD
北大核心
2007年第9期2174-2176,共3页
journal of Computer Applications
关键词
可扩展固件接口
可信链
哈希算法
可信平台模块
数字签名
Extensible Firmware Interfaces (EFI)
trust transition
Hashing algorithm
Trusted Platform Module (TPM)
digital signature