TPM (Trusted Platform Module)-based trusted Web page realization method
A realization method and webpage technology, applied in the direction of electrical components, transmission systems, etc., to achieve the effect of ensuring real association and improving security
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Publication Date
- 2014-04-09
- Estimated Expiration
- Not applicable · inactive patent
Smart Images
Figure 1 Figure 2 Figure 3
Abstract
Description
technical field
[0001] The invention belongs to the field of computer information security, and in particular relates to a method for realizing a TPM-based trusted Web page. Background technique
[0002] With the popularization and promotion of the Internet, Web technology has developed rapidly. figure 1 The working model of Web-based application is given. First, the browser at the client side sends a web page request to the Web server at the web server, and then the Web server returns the corresponding web page to the browser. Both the browser and the Web server are software. With the prevalence of e-commerce, information security issues have become increasingly serious, and the integrity and authenticity of Web page information is one of the security issues. The anti-counterfeiting of a web page is usually considered from the two aspects of the web page provider and the user, that is, the web page provider sends the web page evidence to the customer at the same time, and ...
Examples
Embodiment Construction
[0024]The method provided by the present invention requires the webpage server and the time server to be equipped with a trusted security chip TPM, requires the time server to be equipped with a trusted time generator, requires the webpage server to be installed with a webpage evidence generator, and requires the client to be installed with a Webpage evidence verifier; In addition, the method provided by the present invention assumes that the webpage evidence generator has the system platform state information and the AIK public key certificate of the time server in advance; the webpage evidence verifier has the system platform state information and the AIK public key certificate of the time server in advance , also has the system platform information and AIK public key certificate of the web server.
[0025] The specific work of the trusted time generator includes:
[0026] (1) Serve as the root of trust and maintain a credible time domain, that is, a credible time range. Th...