作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2011, Vol. 37 ›› Issue (4): 137-139. doi: 10.3969/j.issn.1000-3428.2011.04.048

• 安全技术 • 上一篇    下一篇

基于动态安全属性保护的可信固件

周振柳,栾好利,张 楠,杨 政   

  1. (沈阳工程学院电力系统信息安全沈阳市重点实验室,沈阳 110136)
  • 出版日期:2011-02-20 发布日期:2011-02-17
  • 作者简介:周振柳(1971-),男,副教授、博士,主研方向:可信计算,网络安全;栾好利,教授、硕士;张 楠、杨 政,讲师、硕士
  • 基金资助:
    辽宁省教育厅科技研究基金资助项目(L2010386);沈阳市2009年重点实验室建设基金资助项目(1091244-1-00)

Trusted Firmware Based on Dynamic Security Attribute Protection

ZHOU Zhen-liu, LUAN Hao-li, ZHANG Nan, YANG Zheng   

  1. (Shenyang Key Laboratory of Information Security for Power System, Shenyang Institute of Engineering, Shenyang 110136, China)
  • Online:2011-02-20 Published:2011-02-17

摘要: 遵循TCG可信计算的固件通过可信度量和信任传递保证固件模块及OS Loader的完整性。这种可信固件当前实现的缺点在于只保护了系统的静态安全属性,而对动态安全属性保护无能为力。基于此,通过对固件代码和数据的分类研究,对固件代码和数据进行安全分级控制,提出固件动态安全属性保护模型,在EFI/UEFI可信固件的基础上实现动态安全属性的保护。实验证明,该方法简单有效,适合于固件代码尺寸小、启动速度快的要求。

关键词: 静态安全属性, 动态安全属性, 可信计算, 可信固件

Abstract: Trusted firmware compliant with TCG uses trust measurement and trust transition to assure that other modules in firmware and OS Loader are in its integrity. The disadvantage of this method is that it can assure static security attributes about firmware system, but cannot assure dynamic security attributes. Based on study about types of code and data in firmware, a security model assuring dynamic security attribute, which combines trust measurement and classification of code and data, is proposed. Furthermore, this model is simple and efficient enough to meet firmware’s need for small size and fast boot.

Key words: static security attribute, dynamic security attribute, trusted computing, trusted firmware

中图分类号: