摘要
终端代码防篡改技术研究对保护网络终端安全具有重要意义,是信息安全研究的热点问题之一.在分析常见网络终端体系结构脆弱性问题的基础上,提出一种以硬件为核心的终端代码防篡改方案.该方案通过构建独立可执行环境来解决程序运行过程中的完整性保护问题,通过物理隔离和强制访问控制解决数据机密性保护问题.最终采用通用USB-KEY和部分终端代码仿真实现独立可执行设备原型,并对其主要功能和性能进行了测试.实验结果表明,该方案能够利用较低成本的硬件资源,为网络终端内目标程序提供防篡改保护.
The research of terminal code tamper-resistant technology is important to network endpoint security protection which is a hot topic in information security research. With the analysis of vulnerability in common network terminal architecture, a tamper-resistant method which is based on hardware was presented. The method uses the stand-alone executable environment to deal with the issue of integrity protection, and uses the physical isolation and mandatory access control to deal with the issue of confidentiality protection. At last, a simulation prototype system based on proposed method was constructed, which included a general-purpose USB-KEY hard- ware and some PC software modules. The testing of prototype system contains functions and performance test, and the result shows that proposed method, which is based on low-cost hardware resources, is able to provide tamper-resistant protection for target program in the network terminal.
出处
《小型微型计算机系统》
CSCD
北大核心
2013年第12期2809-2813,共5页
Journal of Chinese Computer Systems
基金
国家"八六三"高技术研究发展计划目标导向项目(2009AA01Z434)资助
关键词
信息系统安全
可信计算
代码防篡改
软件保护
information security
trusted computing
tamper proofing
software protection