期刊文献+

基于可信密码模块的SoC可信启动框架模型 被引量:9

An SoC trusted startup framework based on trusted cryptographic module
下载PDF
导出
摘要 为满足嵌入式终端对信息安全的要求,设计了基于可信密码模块的SoC可信启动框架。该框架的特点在于对引导程序U-boot做功能上的分割,且存储在不同的非易失性存储器中,并增设了通信模块,使之在操作系统启动之前就具有发送和接收文件的功能。将引导程序的各部分与操作系统核心文件均作为可信实体,发送至可信密码模块进行完整性度量,若度量成功则可信密码模块返回下一阶段的启动信号并在其本地存储器中保存可信实体;若度量失败则禁止启动。实验结果表明,该框架是可行、有效的,可以满足现今嵌入式终端在信息安全方面的需要。 We design an SoC trusted startup framework based on trusted cryptographic module to satisfy the requirement for information security on embedded terminals. This framework can partition the boot program U-boot functionally and store them in different non-volatile memories. In addition, we add communication modules to enable the U-boot to transmit and receive files before OS stratup. Trusted entities including the parts of the U-boot and OS core files are transmitted to the trusted cryptographic module to measure integrity. If they pass the integrity measurement, then a signal for starting the next phase is sent back by the trusted cryptographic module and the trusted entities are stored in local memory on the trusted cryptographic module. Otherwise initialization signals are not sent. Experimental results show that the proposed framework is feasible and effective, and it can satisfy the requirement for information security on embedded terminals.
作者 王希冀 张功萱 郭子恒 WANG Xi-ji;ZHANG Gong-xuan;GUO Zi-heng(School of Computer Science and Technology,Nanjing University of Science and Technology,Nanjing 210094,China)
出处 《计算机工程与科学》 CSCD 北大核心 2019年第4期606-611,共6页 Computer Engineering & Science
基金 国家自然科学基金(61272420)
关键词 嵌入式终端 系统级芯片 可信密码模块 非易失性存储器 embedded terminal system-level chip trusted cryptographic module non-volatile memory
  • 相关文献

参考文献9

二级参考文献83

共引文献185

同被引文献79

引证文献9

二级引证文献3

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部