Journal on Communications ›› 2018, Vol. 39 ›› Issue (6): 133-145.doi: 10.11959/j.issn.1000-436x.2018090

• Papers • Previous Articles     Next Articles

New extension method of trusted certificate chain in virtual platform environment

Liang TAN1,2,Neng QI1,Lingbi HU1   

  1. 1 College of Computer Science,Sichuan Normal University,Chengdu 610101,China
    2 Institute of Computing Technology,Chinese Academy of Sciences,Beijing 100190,China
  • Revised:2018-03-14 Online:2018-06-01 Published:2018-07-09
  • Supported by:
    The National Natural Science Foundation of China(61373162);Sichuan Science and Technology Project(2014GZ0007);Sichuan Key Laboratory of Visual Computing and Virtual Reality Project(KJ201402)

Abstract:

When using trusted computing technology to build a trusted virtual platform environment,it is a hot problem that how to reasonably extend the underlying physical TPM certificate chain to the virtual machine environment.At present,the certificate trust expansion schemes are not perfect,either there is a violation of the TCG specifications,or TPM and vTPM certificate results inconsistent,either the presence of key redundancy,or privacy CA performance burden,some project cannot even extend the certificate trust.Based on this,a new extension method of trusted certificate chain was proposed.Firstly,a new class of certificate called VMEK (virtual machine extension key) was added in TPM,and the management mechanism of certificate VMEK was constructed,the main feature of which was that its key was not transferable and could be used to sign and encrypt the data inside and outside of TPM.Secondly,it used certificate VMEK to sign vTPM’s vEK to build the trust relationship between the underlying TPM and virtual machine,and realized extension of trusted certificate chain in virtual machine.Finally,in Xen,VMEK certificate and its management mechanism,and certificate trust extension based on VMEK were realized.The experiment results show that the proposed scheme can effectively realize the remote attestation function of virtual platform.

Key words: trusted computing, virtual platform, trusted platform module, vTPM, certificate chain extension

CLC Number: 

No Suggested Reading articles found!