کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
6884331 695293 2013 17 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Tree-formed verification data for trusted platforms
ترجمه فارسی عنوان
داده های تایید درختی برای سیستم عامل های قابل اعتماد
کلمات کلیدی
پلت فرم قابل اعتماد گواهی سنجی از راه دور، درخت هش، سنجش سنجی، داده های تأیید، اعتبار سنجی،
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
چکیده انگلیسی
The establishment of trust relationships to a computing platform relies on validation processes. Validation allows an external entity to build trust in the expected behaviour of the platform based on provided evidence of the platform's configuration. In a process like remote attestation, the 'trusted' platform submits verification data created during a start up process. These data consist of hardware-protected values of platform configuration registers, containing nested measurement values, e.g., hash values, of loaded or started components. Commonly, the register values are created in linear order by a hardware-secured operation. Fine-grained diagnosis of components, based on the linear order of verification data and associated measurement logs, is not optimal. We propose a method to use tree-formed verification data to validate a platform. Component measurement values represent leaves, and protected registers represent roots of a hash tree. We describe the basic mechanism of validating a platform using tree-formed measurement logs and root registers and show a logarithmic speed-up for the search of faults. Secure creation of a tree is possible using a limited number of hardware-protected registers and a single protected operation. In this way, the security of tree-formed verification data is maintained.
ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Computers & Security - Volume 32, February 2013, Pages 19-35
نویسندگان
, , , , ,