摘要
针对目前终端面临的安全隐患,利用可信计算思想,提出了嵌入式可信终端认证原型的设计方案。该方案将口令、生物特征、证书机制和可信认证机制相互融合,构建出用户、终端和应用三层次嵌入式可信终端认证原型,并对可信终端的硬件环境构成、可信引导和可信认证等问题进行了深入分析。该原型对TCG定义的TPM功能进行了扩展和应用,可为嵌入式终端平台提供可信的计算环境。
In this paper, according to the nowadays severe security situation faced by terminal platforms an example of design attestation prototype of embedded trusted terminal is presented based on trusted computing. In this scheme, through combining password, biometric, certificate scheme and trusted attestation scheme, an attestation prototype of embedded trusted terminal is built on three arrangements o.f user and terminal with application, and research on building environment of trusted terminal, the trusted boot and trusted attestation in the paper. Conceptually and functionally extended the TPM defined by TCG in the proposed prototype on embedded platform, and a trusted computing environment is provided for embedded platform.
出处
《信息工程大学学报》
2008年第3期348-351,共4页
Journal of Information Engineering University
基金
国家863计划资助项目(2007AA01Z483)
关键词
嵌入式终端
可信引导
认证
直接匿名认证
embedded terminal
trusted boot
attestation
direct anonymous attestation (DAA)