摘要
基于可信计算的远程证明的方法中,二进制证明方法能反映系统平台当前配置的完整性状态,是动态的,但容易暴露隐私,而基于属性证书的证明将系统平台的配置信息隐藏,具有匿名性,但是静态的.将二进制方法嵌入到属性证书方法中,提出了一种动态属性可信证明(Dynamic Property Trusted Attestation DPTA)的协议.验证者通过模拟计算PCR值,并与证书中的PCR值进行比较,证明示证者的当前平台满足一定的安全属性,解决了暴露隐私和静态问题.实验表明这种证明方法能保护平台隐私,克服基于属性证书的静态特点,兼有实时性和保密性的特点.
In the methods of remote attestation based on trusted computing, binary attestation can reflect real-time status of the plat- form and verify the integrity of remote computing system but easy to disclose privacy, on the other hand, property-based certificate at- testation can conceal platform configuration with anonymity but is static. Binary attestation is embedded into property-based certificate attestation, Dynamic Property Trusted Attestation ( DPTA ) protocol is proposed, which combines their advantages. Verifier checked whether attestor satisfies certain security property through calculating real-time PCR values and comparing with PCR value of certifi- cate. The method has solved privacy exposure and static problems. Experiment verifications show that the scheme can protect the pri- vacy of platform, overcome the static features based on property certificate, and be real time and confidential feature.
出处
《小型微型计算机系统》
CSCD
北大核心
2013年第10期2349-2353,共5页
Journal of Chinese Computer Systems
基金
山西省高等学校科技项目(20101115)资助
山西省科技基础条件平台建设项目(2012091003-0104)资助
山西省科技攻关计划项目(20110321024-02)资助
国家自然基金项目(61273294)资助
关键词
可信计算
可信平台模块
二进制证明
属性证书证明
动态属性可信证明
trusted computing
TPM
binary attestation
property certificate attestation
dynamic property trusted attestation ( DPTA )