摘要
BIOS作为可信计算平台的测量根是可信链的源头,其安全性尤为重要。论文提出了一种基于USBKey的、功能可扩展的安全控制模块增强BIOS安全的设计方案,实现了底层的开机身份认证和安全控制功能,经分析证明此方案可有效地减少可信测量根的不安全因素。
The extended functions ofEFI BIOS take insecurities at the bottom for the computer. As the root of trust for measurement in the chain of trusted, the security of BIOS is very important. Based on USBKey, this paper proposes a design of extensible capability security control model that implements authentication and security controlling at the computer starting. This design has been proved having the ability of reducing the insecurities in the root of trust for measurement.
出处
《信息安全与通信保密》
2007年第12期114-117,共4页
Information Security and Communications Privacy