论文部分内容阅读
针对现有TPM-vTPM PCR映射技术方案的缺点,提出了一种新的从TPM到vTPM的可信映射方法.在此基础上,建立从硬件TPM到vTPM再到客户机操作系统和客户机应用程序的可信链,提出可信虚拟机跨物理主机迁移及可信链快速恢复的方法,分析了可信链迁移方案中的关键技术,开发了原型系统对该方案进行了技术实现.与现有方案相比,本文方案具有易于实现,易于扩展及适应可信链跨物理主机迁移及快速恢复的特点.最后,分析了实现该原型系统时涉及到的关键技术,并分析了该方法的应用前景.
Aiming at the shortcomings of the existing TPM-vTPM PCR mapping scheme, a new method of trusted mapping from TPM to vTPM is proposed.On the basis of this, we establish a hardware architecture from hardware TPM to vTPM to client operating system and client application A trustworthy chain of programs, a method of cross-physical host relocation and credible chain recovery of trusted virtual machines is proposed, key technologies in the trusted chain migration scheme are analyzed, and a prototype system is developed to implement the scheme. Compared with the scheme, this scheme has the characteristics of easy to implement, easy to extend and adapt to the migration and rapid recovery of trusted chain across physical hosts.Finally, the key technologies involved in the implementation of the prototype system are analyzed and the application of the method is analyzed prospect.