Journal on Communications ›› 2015, Vol. 36 ›› Issue (8): 91-103.doi: 10.11959/j.issn.1000-436x.2015139

• Academic paper • Previous Articles     Next Articles

Design and implementation of secure Windows platform based on TCM

Wei FENG,Yu QIN,Deng-guo FENG,Bo YANG,Ying-jun ZHANG   

  1. Trusted Computing and Information Assurance Laboratory,Institute of Software,Chinese Academy of Science,Beijing 100190,China
  • Online:2015-08-25 Published:2015-08-25
  • Supported by:
    The National Natural Science Foundation of China;The National Natural Science Foundation of China

Abstract:

A secure Windows platform solution based on TCM was proposed to solve the integrity measurement and attestation problem of the Windows system.Two security modes were realized by extending the Windows kernel:in the measurement mode,all executable contents that were loaded onto the Windows system were measured,and the TCM provided the protection and outward attestation for these measurements; and in the control mode,the measurements were further compared with a whitelist customized by an administrator,and all the programs that were not included in the whitelist would be prohibited from running.Experiment analysis shows that proposed solution can enhance the security of Windows platform and resist some software attacks; and at the same time,the average performance overhead is about 20~30ms,which will not influence the normal running of Windows.

Key words: trusted computing, integrity measurement, trusted cryptography module, Windows security

No Suggested Reading articles found!