如何扩展传统信任链中的信任传递关系,构建一个可信虚拟化环境,从而保证虚拟域内软件的可信,是可信计算应用到云计算中去的一个关键。该文结合虚拟化技术的特点,提出了一种适用于虚拟化环境的并行信任结构,实现了将信任从虚拟化平台的信任根传递到虚拟域内的应用软件,该信任结构通过在虚拟监控器中加栽一个可信软件保护代理模块,有效的减小了信任中间节点的复杂程度,提高了系统的可控性和安全性。本文还在该结构的基础上设计了一种虚拟机域内高可信软件保护模型,并进行了部分系统实现。
A parallel trust structure is proposed to contain application software into its credence coverage. The structure passes trust from the TPM to the applications in virtual domains. Based on this structure, we design and implement a trusted software protection agent (TSPA), a module in hypervisor, which simplifies the trust complexity and makes trust transfer more controllable and more secure. This paper also contributes a model for protecting software integrity.