A Trusted Software Base for Proactive Security Services
A technology of active security and security service modules, applied in the field of trusted software base, can solve the problems of not providing confidentiality services, and not giving the implementation method of the operating system layer, so as to prevent unauthorized operations and ensure confidentiality and integrity sexual effect
Patent Information
- Authority / Receiving Office
- CN · China
- Current Assignee / Owner
- Publication Date
- 2011-12-07
- Estimated Expiration
- Not applicable · inactive patent
Smart Images
Figure 1 Figure 2 Figure 3
Abstract
Description
technical field
[0001] The invention relates to the field of information security, in particular to a trusted software base that provides active security services and is implemented at the kernel layer of an operating system based on a trusted cryptographic module. technical background
[0002] Existing security protection systems that provide security services for applications are based on personal computer (PC) systems, and most of them implement security protection at the application layer or operating system layer.
[0003] At the beginning of PC design, the main consideration of the system was performance and function, but security was not fully considered. The PC hardware architecture is greatly simplified in terms of security.
[0004] In the PC hardware structure, programs and data are assigned to different segments. When the process is running, a special processor register, sometimes called the base address register, is stored together with the starting address of ...
Examples
Embodiment Construction
[0030] Below in conjunction with accompanying drawing of description, specific embodiment of the present invention is described:
[0031] see figure 1 Shown is a schematic diagram of the trusted software base composition structure.
[0032] The trusted software base consists of a trusted cryptographic module, a kernel-level trusted cryptographic module driver, a kernel-level trusted software stack, and a kernel-level security service module. The kernel-level security service module is composed of a security policy server and a security manager.
[0033] see figure 2 As shown in , it is a schematic diagram of the hardware composition of the trusted cryptographic module.
[0034] The trusted cryptographic module is embedded in the PC motherboard. It is an independent hardware entity, mainly composed of CPU, single storage unit, cryptographic algorithm engine, active measurement module and so on. It receives the command data stream delivered by the kernel-level trusted cryp...