通信学报 ›› 2015, Vol. 36 ›› Issue (8): 91-103.doi: 10.11959/j.issn.1000-436x.2015139

• 学术论文 • 上一篇    下一篇

基于TCM的安全Windows平台设计与实现

冯伟,秦宇,冯登国,杨波,张英骏   

  1. 中国科学院软件研究所 可信计算与信息保障实验室,北京 100190
  • 出版日期:2015-08-25 发布日期:2015-08-25
  • 基金资助:
    国家自然科学基金资助项目;国家自然科学基金资助项目;国家重点基础研究发展计划(“973”计划)基金资助项目

Design and implementation of secure Windows platform based on TCM

Wei FENG,Yu QIN,Deng-guo FENG,Bo YANG,Ying-jun ZHANG   

  1. Trusted Computing and Information Assurance Laboratory,Institute of Software,Chinese Academy of Science,Beijing 100190,China
  • Online:2015-08-25 Published:2015-08-25
  • Supported by:
    The National Natural Science Foundation of China;The National Natural Science Foundation of China

摘要:

为了解决 Windows 系统的完整性度量与证明问题,提出了一种基于可信密码模块 TCM(trusted cryptography module)的安全Windows平台方案。通过扩展Windows内核实现了2种安全模式:在度量模式下,所有加载的可执行程序都会被度量,度量值由 TCM 提供保护和对外认证;在管控模式下,度量值会进一步与管理员定制的白名单进行匹配,禁止所有不在白名单中的程序执行。实验分析表明,该方案可以增强Windows系统的安全性,抵抗一些软件攻击行为;同时,系统平均性能消耗在20~30ms之间,不会影响Windows的正常运行。

关键词: 可信计算, 完整性度量, 可信密码模块, Windows安全

Abstract:

A secure Windows platform solution based on TCM was proposed to solve the integrity measurement and attestation problem of the Windows system.Two security modes were realized by extending the Windows kernel:in the measurement mode,all executable contents that were loaded onto the Windows system were measured,and the TCM provided the protection and outward attestation for these measurements; and in the control mode,the measurements were further compared with a whitelist customized by an administrator,and all the programs that were not included in the whitelist would be prohibited from running.Experiment analysis shows that proposed solution can enhance the security of Windows platform and resist some software attacks; and at the same time,the average performance overhead is about 20~30ms,which will not influence the normal running of Windows.

Key words: trusted computing, integrity measurement, trusted cryptography module, Windows security

No Suggested Reading articles found!