Multi-case dynamic remote certification method based on TPM

A remote attestation, multi-instance technology, applied in the field of information security

CN101344903AInactive Publication Date: 2009-01-14INST OF SOFTWARE - CHINESE ACAD OF SCI
0 Cites 16 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Publication Date
2009-01-14
Estimated Expiration
Not applicable · inactive patent

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The invention discloses a TPM-based multi-instance dynamic remote attestation method which belongs to the field of information security technology. The method comprises the steps as follows: a) an RAI instance is started: the TPM measures the RAI instance and issues an initial attestation certificate for the RAI instance; the remote relying party of the RAI instance obtains and authenticates the initial attestation certificate, if the authentication is passed, the link between the RAI instance and the remote relying party of the RAI instance is established; b) if the component of the RAI instance is updated, the TPM re-measures the RAI instance and issues an updating attestation certificate; the remote relying party of the RAI instance obtains and authenticates the updating attestation certificate; if the authentication is passed, the link is maintained; and c) the step b) is repeated until the RAI instance is closed and the link is disconnected; meanwhile, all the attestation steps of a plurality of RAI instances intersperse with each other for forming a TPM attestation chain. Compared with the remote attestation methods of other trusted computing platforms, the method is characterized by the dynamic attestation of platform status, the concurrent attestations of multiple network programs, and anti-replay attack, etc.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The invention relates to a TPM-based multi-instance dynamic remote attestation method. Specifically, the invention relates to a trusted computing platform-based remote attestation method for concurrently attesting to the credibility of multiple RAI instances and their operating environments. The invention belongs to the technical field of information security. Background technique

[0002] In 1999, several major companies such as Compaq, HP, IBM, Intel, and Microsoft led the establishment of TCPA (Trusted Computing Platform Alliance), and more than 200 computer companies / enterprises around the world joined it. In 2001, the organization launched the Trusted Computing Module (Trusted Platform Module) : TPM) 1.1 related software and hardware technical specifications. In 2003, TCPA was reorganized into TCG (Trusted Computing Group), with the goal of comprehensively promoting trusted computing technology from an industrial perspective, and launched the TPM...

Examples

Embodiment Construction

[0054] Below in conjunction with specific embodiment and accompanying drawing, the present invention is further described:

[0055] The main states in the MRAI attestation running cycle in this embodiment include: creating a new RAI session, RAI initial attestation, RAI state update attestation, and RAI session closing, as shown in the appendix figure 2 shown. Each RAI is in one of these four states, and multiple RAIs are running on the system at the same time, and concurrently use the same TPM to prove the running state. Among the four states of RAI, the state S0 to S3 is a one-way transition process, except that the state S2 can be continuously in a cyclic state.

[0056] The main states of MRAI proofs and their transformations will be described in detail below.

[0057] 1. New session state

[0058] When a RAI instance is in the new session state, that is, the RAI instance program has just started running, the TPM management module located in the trusted service layer w...