作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (15): 7-9. doi: 10.3969/j.issn.1000-3428.2008.15.003

• 博士论文 • 上一篇    下一篇

基于TPM的终端数据可信迁移研究

王 飞1,2,李 勇1,郭东文2   

  1. (1. 解放军信息工程大学电子技术学院,郑州 450004;2. 装备指挥技术学院,北京 101416)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-08-05 发布日期:2008-08-05

Research on Trusted Transfer of Terminal Data Based on TPM

WANG Fei1,2, LI Yong1, GUO Dong-wen2   

  1. (1. Electronic Techndogy Institute, PLA Information Engineering University, Zhengzhou 450004; 2. Academy of Equipment Command & Technology, Beijing 101416)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-08-05 Published:2008-08-05

摘要: 提出一种终端数据可信迁移方案以解决数据无防护地流入/流出终端所带来的安全问题。根据“全程BLP规则”对待流入/流出的数据进行安全检查,只允许符合安全策略的数据迁移,由TPM负责将其加密/解密。介绍实现框架并分析其安全性。该方案可以保证迁移数据的机密性和可控性。

关键词: 可信计算, 可信平台模块, 终端数据, 可信迁移

Abstract: This paper presents a method of terminal data trusted transfer to solve the security problems, which are caused by data flowing in or out of terminals. According to “overall BLP model”, the data to flow in or out of terminals are checked, and only those matching the security policies can be transferred, which are encrypted or decrypted by TPM at the same time. It gives an implementation framework of the method, and analyzes its security. The method can insure that transferred data is confidential and controllable.

Key words: trusted computing, Trusted Platform Module(TPM), terminal data, trusted transfer

中图分类号: