嵌入式系统在生活中不可或缺,如何增强其安全性是急需解决的问题;现有解决办法局限于理论层面且不符合嵌入式系统实际需求;为实现嵌入式系统安全启动并满足其实际应用需求,设计并实现了嵌入式系统可信启动机制;该机制以可信计算理论为基础,提出一种适用于嵌入式环境的高效、透明的可信框架模型,设计完成嵌入式可信计算硬件模块(ETHM)以及其逻辑结构,构造可靠稳定的接口机制,实现了完整的可信链传递、操作系统高可信启动机制等技术的集成设计;通过实验验证,该可信机制对操作系统安全性可以进行准确判定,并做出正常启动或发出警告的正确指令;实验结果表明,该可信机制具备安全性、可靠性、高效性的特点,并满足嵌入式系统实际应用需求.
The embedded system is very important in our life. How to improve the security of the embedded system is currently an im portant topic. The existing solution is just theoretical and does not conform to the actual demand of embedded system. To realize the secure initiation of the embedded system and meet the demand of its practical application, this paper designed and realized a trusted initiated mechanism of embedded system. The mechanism is built on the theory of trusted computing, and put forward an efficient, transparent, credible framework model which is suitable for the embedded environment. And this paper designed the hardware structure and logical structure of embedded trusted hardware module (ETHM), constructed a reliable and stable interface machine, and then realized an integration design of complete trusted chain technology and operating system high reliable initiated mechanism. During experimental verification, the trusted mechanism can accurately determine the security of operating system, and make the correct order for the normal start or warning. The experimental results show that the initiated mechanism has the characteristics of safety, reliability and high efficiency, and meet the demand of practical application.