TPM (Trusted Platform Module)-based trusted Web page realization method

A realization method and webpage technology, applied in the direction of electrical components, transmission systems, etc., to achieve the effect of ensuring real association and improving security

CN102355459BInactive Publication Date: 2014-04-09BEIJING JIAOTONG UNIV
5 Cites 2 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Publication Date
2014-04-09
Estimated Expiration
Not applicable · inactive patent

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The invention relates to a TPM (Trusted Platform Module)-based trusted Web page realization method. Components for the method comprise a client end, a web page server end and a time server end, wherein the web page server end comprises a web page evidence generator, the client end comprises a web page evidence verifier, and the time server end comprises a trusted time generator; the trusted time generator is used for providing trusted time for the web page evidence generator and the web page evidence verifier; the web page evidence generator adopts the TPM arranged at the web page server end to generate web page evidences with the trusted time and web page contents for the web page; and the web page evidence verifier is used for verifying the credibility of the web page according to the received web page, the web page evidences and the trusted time. Due to collaboration of the three components, a user can verify the integrity and authenticity of the web page while browsing the web page.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The invention belongs to the field of computer information security, and in particular relates to a method for realizing a TPM-based trusted Web page. Background technique

[0002] With the popularization and promotion of the Internet, Web technology has developed rapidly. figure 1 The working model of Web-based application is given. First, the browser at the client side sends a web page request to the Web server at the web server, and then the Web server returns the corresponding web page to the browser. Both the browser and the Web server are software. With the prevalence of e-commerce, information security issues have become increasingly serious, and the integrity and authenticity of Web page information is one of the security issues. The anti-counterfeiting of a web page is usually considered from the two aspects of the web page provider and the user, that is, the web page provider sends the web page evidence to the customer at the same time, and ...

Examples

Embodiment Construction

[0024]The method provided by the present invention requires the webpage server and the time server to be equipped with a trusted security chip TPM, requires the time server to be equipped with a trusted time generator, requires the webpage server to be installed with a webpage evidence generator, and requires the client to be installed with a Webpage evidence verifier; In addition, the method provided by the present invention assumes that the webpage evidence generator has the system platform state information and the AIK public key certificate of the time server in advance; the webpage evidence verifier has the system platform state information and the AIK public key certificate of the time server in advance , also has the system platform information and AIK public key certificate of the web server.

[0025] The specific work of the trusted time generator includes:

[0026] (1) Serve as the root of trust and maintain a credible time domain, that is, a credible time range. Th...