文档介绍:可信PDA计算平台系统结构与安全机制*项目支持:国家自然科学基金(60673071,60970115)和国家863计划项目(2006AA01Z442,2007AA01Z411)
作者简介:赵波(1972-),男,博士,副教授,主要研究方向为可信计算、张焕国(1945-),男,教授,主要研究方面:信息安全、可信计算;
The System architecture and Security structure of Trusted PDA
Bo Zhao 1,2 Huanguo Zhang 1,2 Li Jing 1,2 Chen Lu 1,2 Wen song 1,2
puter School, Wuhan University, Hubei, China)
2(State Key Lab of Software Engineering, Wuhan University, Hubei, China)
E-mail: ******@whu.
摘要: PDA作为一种手持设备,面临着众多的安全问题。本文介绍利用可信计算思想构造了可信PDA的体系结构与安全机制。文中提出了一种带数据恢复功能的星型信任结构,其在安全性、效率及可靠性等方面较TCG的链式信任结构都有很大提升。在此基础上,进一步使用总线仲裁等技术构造了可信PDA的体系结构模型。文中还提出并实现了针对可信PDA嵌入式操作系统的安全增强、基于可信PDA平台的可信网络连接(TNC)以及SD卡全盘加密等新的安全技术与方法。在此基础上,研制出我国第一款可信PDA的原型系统。经过实验验证,这款可信PDA在各方面都达到了可信计算平台的技术要求。
关键词:可信计算;可信计算平台;可信PDA;星型信任结构
Abstract PDA as a handheld device, faced with a number of security issues. This article describes the Trusted PDA architecture and security mechanism by using the method of puting. This paper proposes a “star-style” chain of trusted structure with data recovery functions, and it owns more safety, efficiency and reliability than the TCG trust structure .On this basis, the further use of technologies such as bus arbitration system constructed a trusted structural model of PDA. The paper also proposed and implemented a security enhanced embedded operating system for the trusted PDA. Based on trusted platform
,work Connect (TNC), as well as SD cards full-disk encryption and other new security technologies and methods can be solved. On this basis, we developed the first trusted PDA-prototype system in China. After experimental verification, this PDA has reached all aspects of the technical requirements of the puting Platform.
Keywords: puting, puting platform, trusted PDA, star-style chain of trusted structure
中图分类号:TP309 文献标识码:A
0、引言
长期以来,很多人认为PDA系统的软件是固化在硬件芯片里面的,不存在被攻击的可能性,因此对于PDA系统的安全问题,业界并没有给予重视和研究。然而,随着PDA的技术发展与广泛应用,PDA也面临着巨大的安全威胁:首先,PDA是一种手持移动设备,容易丢失,由此可能被冒用,造成信息泄露;其次,由于存储器技术的发展,PDA的存储器越来越多的采用可编程FLASH器件。因此病毒等恶意代码完全可以攻击PDA系统;再其次,PDA