首页> 外文会议>International Conference for Young Computer Scientists >A Secure and Reliable Platform Configuration Change Reporting Mechanism for Trusted Computing Enhanced Secure Channels
【24h】

A Secure and Reliable Platform Configuration Change Reporting Mechanism for Trusted Computing Enhanced Secure Channels

机译:一种安全可靠的平台配置更改可信计算增强的安全通道的报告机制

获取原文

摘要

The security of well established secure channel technologies like transport layer security (TLS) or IP security (IPSec) can be significantly improved by emerging concepts like Trusted Computing. The use of trusted platform modules (TPMs) offers new methods for improving the security of these well established technologies. How secure channel technologies can be adapted to use trusted computing concepts is subject to current research. A major part of this research addresses the integration of the TCG's specified remote attestation. Remote attestation enables a platform to provide a trustworthy proof of its current configuration (i.e. software that has been loaded on the platform). Hence, based on this proof, a remote platform can decide whether to open a channel to another platform or not. In current approaches, the proof of the platform configuration is processed before a secure channel is established, which is not opened if the reported configuration is not accepted by the hosts. However, one important problem has not been solved yet. Currently, no satisfying solution how the change of a platform's configuration can be securely and reliably reported to the remote platform whilst a channel is open, exists. A reliable method to provide a prooffor a configuration change can be implemented with only minor modifications of the TPM specification and the TLS protocol. Experimental results show that it is possible to implement this proof mechanism with only a few additional TPM commands.
机译:通过可信计算等新兴的概念,可以显着改善良好的安全层安全(TLS)或IP安全性(IPSec)等安全频道技术的安全性。使用可信平台模块(TPMS)提供了提高这些知名技术安全性的新方法。如何适应使用可信计算概念的安全渠道技术符合当前的研究。本研究的主要部分地址解决了TCG指定远程证明的集成。远程证明使平台能够提供其当前配置的值得信赖的证据(即已在平台上加载的软件)。因此,基于此证明,远程平台可以决定是否将频道打开到另一个平台。在当前方法中,在建立安全通道之前处理平台配置的证明,如果主机不接受报告的配置,则不会打开。但是,尚未解决一个重要问题。目前,没有令人满意的解决方案如何将平台配置的变化能够安全可靠地向远程平台报告,同时频道打开,存在。提供Profrofor的可靠方法可以仅用TPM规范和TLS协议进行次要修改来实现配置改变。实验结果表明,只有几个额外的TPM命令也可以实现这种证明机制。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号